Anyray connect — points local coding tools (Claude Code, Cursor, Windsurf, SDKs) at the Anyray gateway through supported configuration and enrolled personal authentication.
No unconsented install or import-time attack surface was found. The CLI can configure AI tools, persist a per-user refresh service, and use a Copilot token only during explicit setup.
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/managed.jsView on unpkg · L58Source writes installer persistence such as shell profile or service configuration.
dist/commands/managed.jsView on unpkg · L58Source appears to send environment or credential material to an external endpoint.
dist/util/copilotSeatToken.jsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/commands/acpAgent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/cursor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/appQuit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/claudeImporter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/refreshScheduler.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/managed.jsView on unpkg · L58Source writes installer persistence such as shell profile or service configuration.
dist/commands/managed.jsView on unpkg · L58Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/commands/acpAgent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/cursor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/appQuit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/claudeImporter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/refreshScheduler.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/util/copilotSeatToken.jsView on unpkg · L26