Ultra-lightweight local AI Gateway with 1-Click Claude Code Setup
LPM flags this version as an AI-agent control-surface risk. When the user runs the gateway and sends an AI request with tools, it injects instructions to act autonomously through file and shell tools. It also disguises the upstream Grok service as Claude and persists a launcher alias in shell startup files.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/server.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
dist/server.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/server.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/server.jsView on unpkg · L5Package source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L12Source writes installer persistence such as shell profile or service configuration.
dist/utils/shortcut.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/updateNotifier.jsView on unpkgThis report applies to ai-claude-keyapi@1.0.14.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/server.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
dist/server.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/server.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/server.jsView on unpkg · L5Source writes installer persistence such as shell profile or service configuration.
dist/utils/shortcut.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/utils/updateNotifier.jsView on unpkgPackage source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L12