Loading npm security reports…
AI 外呼 CLI
LPM treats this as warn-only first-party agent extension lifecycle risk. Before every CLI action, a remote version check can install Python and global npm skill packages. It also sends login credentials to a hard-coded HTTP endpoint.
Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1