Xyne CLI - A powerful AI assistant in your terminal with file operations, bash mode, drag-and-drop support, and multi-provider AI integration
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references child process execution.
dist-lib/src/pets/hosts/macos/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist-lib/src/agent/runtime/testing/llm-request-capture.jsView on unpkg · L21Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/jimp/dist/browser/index.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L40Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage ships native binary artifacts.
node_modules/@opentui/core-darwin-arm64/libopentui.dylibView on unpkgPackage ships WebAssembly modules.
node_modules/@opentui/core/assets/zig/tree-sitter-zig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/exif-parser/MakefileView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/src/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/src/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-lib/src/agent/tools/goal/extension.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-lib/src/utils/local-server.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-lib/src/agent/runtime/embedded-pi-runtime.jsView on unpkgThis report applies to @xyne/xyne-cli@0.4.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L102Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L102Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L148Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L148Package source references child process execution.
dist-lib/src/pets/hosts/macos/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/jimp/dist/browser/index.jsView on unpkg · L1Package ships native binary artifacts.
node_modules/@opentui/core-darwin-arm64/libopentui.dylibView on unpkgPackage ships WebAssembly modules.
node_modules/@opentui/core/assets/zig/tree-sitter-zig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/exif-parser/MakefileView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/src/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/src/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-lib/src/agent/tools/goal/extension.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-lib/src/utils/local-server.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-lib/src/agent/runtime/embedded-pi-runtime.jsView on unpkgPackage source references dynamic require/import behavior.
dist-lib/src/agent/runtime/testing/llm-request-capture.jsView on unpkg · L21Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L40Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkg