AI Agent Task Management Dashboard
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically alters the compiled code of a third-party Claude ACP agent. The mutation occurs before the user invokes the package.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/runtime/acp/agents/native-agent.jsView on unpkg · L1Package source references shell execution.
dist/runtime/acp/process-manager.jsView on unpkg · L479Package source references a known benign dynamic code generation pattern.
vendor/pi/examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references dynamic require/import behavior.
dist/web/assets/index-DJqjl4es.jsView on unpkg · L12Package source executes code through a VM context API.
dist/utils/process-launch.test.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/@prisma/client/runtime/binary.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
Package source invokes a package manager install command at runtime.
node_modules/@shitiandmw/node-pty/scripts/gen-compile-commands.jsView on unpkg · L7Package ships native binary artifacts.
node_modules/@shitiandmw/node-pty/third_party/conpty/1.23.251008001/win10-arm64/conpty.dllView on unpkgPackage ships WebAssembly modules.
vendor/pi/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
vendor/pi/bin/pi.cmdView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/web/assets/ts.worker-BH9nVgjN.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/executors/default-profiles.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@shitiandmw/node-pty/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@shitiandmw/node-pty/lib/windowsPtyAgent.jsView on unpkgThis report applies to agent-tower@0.7.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references weak cryptographic algorithms.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
node_modules/@prisma/client/runtime/binary.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31Package source references child process execution.
dist/runtime/acp/agents/native-agent.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/web/assets/index-DJqjl4es.jsView on unpkg · L12Package source executes code through a VM context API.
dist/utils/process-launch.test.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/@prisma/client/runtime/binary.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
Package source invokes a package manager install command at runtime.
node_modules/@shitiandmw/node-pty/scripts/gen-compile-commands.jsView on unpkg · L7Package ships native binary artifacts.
node_modules/@shitiandmw/node-pty/third_party/conpty/1.23.251008001/win10-arm64/conpty.dllView on unpkgPackage ships WebAssembly modules.
vendor/pi/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
vendor/pi/bin/pi.cmdView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/web/assets/ts.worker-BH9nVgjN.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/executors/default-profiles.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@shitiandmw/node-pty/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@shitiandmw/node-pty/lib/windowsPtyAgent.jsView on unpkgPackage source references shell execution.
dist/runtime/acp/process-manager.jsView on unpkg · L479Package source references a known benign dynamic code generation pattern.
vendor/pi/examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references weak cryptographic algorithms.
vendor/pi/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
node_modules/@prisma/client/runtime/binary.jsView on unpkg · L1