Open-source, self-hosted autonomous AI agent on Telegram, Slack, Discord, WhatsApp, Signal, terminal & web. Claude Agent SDK + multi-provider engine with auto-failover, detached sub-agents, zero-config memory. Local-first, telemetry-free.
LPM treats this as warn-only first-party agent extension lifecycle risk. Starting the bot under its macOS launchd configuration invokes a self-installing dead-man watcher. This is first-party persistence for the Alvin Bot process, not an npm install-time action.
Package source references child process execution.
claude-bridge/src/claude.jsView on unpkg · L2Package source references dynamic require/import behavior.
claude-bridge/src/claude.jsView on unpkg · L2Package source references weak cryptographic algorithms.
claude-bridge/src/claude.jsView on unpkg · L2Manifest entrypoint contains risky behavior absent from dist/build output.
bin/cli.jsView on unpkg · L22A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/cli.jsView on unpkg · L1312Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/services/browser-manager.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/middleware/auth.jsView on unpkg · L1Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/cli.jsView on unpkg · L22Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/cli.jsView on unpkg · L22A manifest entrypoint or package-local install chain reaches persistence behavior.
bin/cli.jsView on unpkg · L22Package source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L296Source writes installer persistence such as shell profile or service configuration.
bin/cli.jsView on unpkg · L22Package source references a known benign dynamic code generation pattern.
bin/cli.jsView on unpkg · L4343Package source references child process execution.
claude-bridge/src/claude.jsView on unpkg · L2Package source references dynamic require/import behavior.
claude-bridge/src/claude.jsView on unpkg · L2Package source references weak cryptographic algorithms.
claude-bridge/src/claude.jsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/services/browser-manager.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/middleware/auth.jsView on unpkg · L1Manifest entrypoint contains risky behavior absent from dist/build output.
bin/cli.jsView on unpkg · L22Source writes installer persistence such as shell profile or service configuration.
bin/cli.jsView on unpkg · L22A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/cli.jsView on unpkg · L1312Package source references a known benign dynamic code generation pattern.
bin/cli.jsView on unpkg · L4343Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/cli.jsView on unpkg · L22Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/cli.jsView on unpkg · L22A manifest entrypoint or package-local install chain reaches persistence behavior.
bin/cli.jsView on unpkg · L22Package source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L296