1const e=require(`./auth-BCy-04wW.js`);let t=require(`commander`);t=e.G(t);let n=require(`node:crypto`);n=e.G(n);let r=require(`node:fs`);r=e.G(r);let i=require(`node:os`);i=e.G(i);...
L2: `)}function pt(e){if(!e||typeof e!=`string`)return e;try{return JSON.parse(e)}catch{return e}}function A(...e){return e.find(e=>e!=null&&e!==``)}function mt(e){if(e==null||e===``)r...
...
L4: `)}catch{}},y=()=>{try{r.write(`MCP proxy failed.
L5: `)}catch{}},b=()=>{_===void 0&&(_={kind:`factory`,reported:!1})},x=t=>(h||(g=t,h=(async()=>{v();let n,r=async e=>{try{await e()}catch(e){n===void 0&&(n=e)}};for(await u.catch(e=>{n...
L6: `),i);let o=await new Promise((e,t)=>{let n=f.default.createInterface({input:r,output:i,terminal:!0}),a=!1,o=()=>r.removeListener(`error`,c),s=e=>{a||(a=!0,o(),n.close(),t(e)
CriticalAi Agent Control Hijack
Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
dist/cli.jsView on unpkg · L1 1const e=require(`./auth-BCy-04wW.js`);let t=require(`commander`);t=e.G(t);let n=require(`node:crypto`);n=e.G(n);let r=require(`node:fs`);r=e.G(r);let i=require(`node:os`);i=e.G(i);...
L2: `)}function pt(e){if(!e||typeof e!=`string`)return e;try{return JSON.parse(e)}catch{return e}}function A(...e){return e.find(e=>e!=null&&e!==``)}function mt(e){if(e==null||e===``)r...
...
L4: `)}catch{}},y=()=>{try{r.write(`MCP proxy failed.
L5: `)}catch{}},b=()=>{_===void 0&&(_={kind:`factory`,reported:!1})},x=t=>(h||(g=t,h=(async()=>{v();let n,r=async e=>{try{await e()}catch(e){n===void 0&&(n=e)}};for(await u.catch(e=>{n...
L6: `),i);let o=await new Promise((e,t)=>{let n=f.default.createInterface({input:r,output:i,terminal:!0}),a=!1,o=()=>r.removeListener(`error`,c),s=e=>{a||(a=!0,o(),n.close(),t(e)
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L1 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/cli.js:
const e=require(`./auth-BCy-04wW.js`);let t=require(`commander`);t=e.G(t);let n=require(`node:crypto`);n=e.G(n);let r=require(`node:fs`);r=e.G(r);let i=require(`node:os`);i=e.G(i);...
`)}function pt(e){if(!e||typeof e!=`string`)return e;try{return JSON.parse(e)}catch{return e}}function A(...e){return e.find(e=>e!=null&&e!==``)}function mt(e){if(e==null||e===``)r...
`))t&&M(t)}let r=wt(t);t.wait?kt(t.wait,{ai:r}):t.watch?kt(t.watch,{ai:r}):Ot(t)?kt(t,{printJobId:!t.jobId,ai:r}):r&&Tt(t);let i=Et(t);if(!t.wait?.outputs?.length&&!t.watch?.output...
`)}catch{}},b=()=>{_===void 0&&(_={kind:`factory`,reported:!1})},x=t=>(h||(g=t
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkg 1const e=require(`./auth-BCy-04wW.js`);let t=require(`commander`);t=e.G(t);let n=require(`node:crypto`);n=e.G(n);let r=require(`node:fs`);r=e.G(r);let i=require(`node:os`);i=e.G(i);...
L2: `)}function pt(e){if(!e||typeof e!=`string`)return e;try{return JSON.parse(e)}catch{return e}}function A(...e){return e.find(e=>e!=null&&e!==``)}function mt(e){if(e==null||e===``)r...
L3: `))t&&M(t)}let r=wt(t);t.wait?kt(t.wait,{ai:r}):t.watch?kt(t.watch,{ai:r}):Ot(t)?kt(t,{printJobId:!t.jobId,ai:r}):r&&Tt(t);let i=Et(t);if(!t.wait?.outputs?.length&&!t.watch?.output...
L4: `)}catch{}},y=()=>{try{r.write(`MCP proxy failed.
L5: `)}catch{}},b=()=>{_===void 0&&(_={kind:`factory`,reported:!1})},x=t=>(h||(g=t,h=(async()=>{v();let n,r=async e=>{try{await e()}catch(e){n===void 0&&(n=e)}};for(await u.catch(e=>
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L1 1Trigger-reachable command-output exfiltration chain: scripts.postinstall -> bin/postinstall.js -> dist/cli.js
L1: const e=require(`./auth-BCy-04wW.js`);let t=require(`commander`);t=e.G(t);let n=require(`node:crypto`);n=e.G(n);let r=require(`node:fs`);r=e.G(r);let i=require(`node:os`);i=e.G(i);...
L2: `)}function pt(e){if(!e||typeof e!=`string`)return e;try{return JSON.parse(e)}catch{return e}}function A(...e){return e.find(e=>e!=null&&e!==``)}function mt(e){if(e==null||e===``)r...
L3: `))t&&M(t)}let r=wt(t);t.wait?kt(t.wait,{ai:r}):t.watch?kt(t.watch,{ai:r}):Ot(t)?kt(t,{printJobId:!t.jobId,ai:r}):r&&Tt(t);let i=Et(t);if(!t.wait?.outputs?.length&&!t.watch?.output...
L4: `)}catch{}},y=()=>{try{r.write(`MCP proxy failed.
L5: `)}catch{}},b=()=>{_===void 0&&(_={kind:`factory`,reported:!1})},x=t
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L1