Agent-board dashboard for Pi: dispatch, monitor, peek/reply, and attach to background Pi sessions.
No confirmed malicious attack surface was established. The postinstall hook replaces two named nested dependency copies; runtime process and clipboard actions are dashboard features.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package has an automatic postinstall hook.
package.jsonView on unpkg · L52Package source references child process execution.
runner/state-runner.mjsView on unpkg · L8Package source references weak cryptographic algorithms.
src/core/auto-state.mjsView on unpkg · L25Package source invokes a package manager install command at runtime.
scripts/patch-vulns.mjsView on unpkg · L46This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/ui/pty-attach.tsView on unpkgThis report applies to @zhuxixi/pi-agent-board@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L53The package has an automatic postinstall hook.
package.jsonView on unpkg · L52This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/ui/pty-attach.tsView on unpkgPackage source references child process execution.
runner/state-runner.mjsView on unpkg · L8Package source references weak cryptographic algorithms.
src/core/auto-state.mjsView on unpkg · L25Package source invokes a package manager install command at runtime.
scripts/patch-vulns.mjsView on unpkg · L46