AgentsWorkStudio runtime bridge service for machine-level agent runtime integration
npm installation can modify the host operating system and download a browser without a separate user command. On root Linux installs it runs package-manager commands and asks Playwright to install Chromium with system dependencies.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgPackage source references dynamic require/import behavior.
dist/utils/sdk-package-loader.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/routes/instance.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/services/cli-commands.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/services/cli-commands.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/adapter/OpencodeSdkAdapter.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/adapter/OpencodeSdkAdapter.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/ensure-playwright-browser.mjsView on unpkg · L20Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ensure-playwright-browser.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/playwright/lib/common/index.jsView on unpkg · L65Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/common/index.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
node_modules/playwright-core/lib/vite/traceViewer/assets/codeMirrorModule-By56iMx7.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L470Package ships WebAssembly modules.
package/acode/dist/grammars/grammars/tree-sitter-go.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/playwright-core/bin/reinstall_msedge_dev_win.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/remote-desktop/system-backend.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/runner/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/adapter/ClaudeSdkAdapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
package/acode/dist/background-command-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/pty.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/plugin-manager.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L42Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/playwright/lib/common/index.jsView on unpkg · L65Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/common/index.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
node_modules/playwright-core/lib/vite/traceViewer/assets/codeMirrorModule-By56iMx7.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L470Package ships WebAssembly modules.
package/acode/dist/grammars/grammars/tree-sitter-go.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
node_modules/playwright-core/bin/reinstall_msedge_dev_win.ps1View on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/remote-desktop/system-backend.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/runner/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/adapter/ClaudeSdkAdapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/terminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
package/acode/dist/background-command-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/git.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/routes/pty.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/plugin-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgPackage source references dynamic require/import behavior.
dist/utils/sdk-package-loader.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/routes/instance.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/services/cli-commands.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/services/cli-commands.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/adapter/OpencodeSdkAdapter.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/adapter/OpencodeSdkAdapter.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/ensure-playwright-browser.mjsView on unpkg · L20Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ensure-playwright-browser.mjsView on unpkg