Loading npm security reports…
AI 外呼 CLI
LPM treats this as warn-only first-party agent extension lifecycle risk. No install-time execution is present. When a user runs the CLI update command, it can globally install multiple latest-tag skill packages; login submits credentials to a fixed HTTP endpoint.
Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1