Agent-board dashboard for Pi: dispatch, monitor, peek/reply, and attach to background Pi sessions.
No malicious attack surface is confirmed. The install hook patches two named nested dependencies, while runtime subprocesses implement the advertised user-invoked Pi background-agent dashboard.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
runner/state-runner.mjsView on unpkg · L8Package source references weak cryptographic algorithms.
src/core/auto-state.mjsView on unpkg · L25Package source invokes a package manager install command at runtime.
scripts/patch-vulns.mjsView on unpkg · L46Postinstall replaces two hard-coded nested dependencies via npm with scripts disabled.
scripts/patch-vulns.mjsView on unpkg · L25This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/ui/pty-attach.tsView on unpkgThis report applies to @zhuxixi/pi-agent-board@0.4.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L53This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/ui/pty-attach.tsView on unpkgPackage source references child process execution.
runner/state-runner.mjsView on unpkg · L8Package source references weak cryptographic algorithms.
src/core/auto-state.mjsView on unpkg · L25Postinstall replaces two hard-coded nested dependencies via npm with scripts disabled.
scripts/patch-vulns.mjsView on unpkg · L25Package source invokes a package manager install command at runtime.
scripts/patch-vulns.mjsView on unpkg · L46