Ultra-fast local agent shell for Windows.
At runtime, the application can transfer credentials read from OpenCode authentication storage to opencode.ai. Its agent can also fetch and execute an unsigned remote driver installer.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/beast-agent.jsView on unpkgPackage source references dynamic require/import behavior.
bin/beast-agent.jsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/main.jsView on unpkg · L5Package source references weak cryptographic algorithms.
src/agent/mem0.jsView on unpkg · L29A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/agent/searxng.jsView on unpkg · L15Manifest-reachable source overwrites another installed package with package-defined remote behavior.
src/agent/store.jsView on unpkgSource downloads or fetches remote code and executes it.
src/agent/tools.jsView on unpkg · L5Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/agent/computeruse.jsView on unpkg · L8Package source invokes a package manager install command at runtime.
bin/beast-agent.js#virtual:normalized:round1View on unpkg · L29Package ships non-JavaScript build or shell helper files.
src/agent/scripts/mt5_bridge.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/bus.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/config.jsView on unpkgThis report applies to beast-agent@2.38.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43Manifest-reachable source overwrites another installed package with package-defined remote behavior.
src/agent/store.jsView on unpkgSource downloads or fetches remote code and executes it.
src/agent/tools.jsView on unpkg · L5Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/agent/computeruse.jsView on unpkg · L8Package source invokes a package manager install command at runtime.
bin/beast-agent.js#virtual:normalized:round1View on unpkg · L29Package ships non-JavaScript build or shell helper files.
src/agent/scripts/mt5_bridge.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/bus.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/config.jsView on unpkgPackage source references dynamic require/import behavior.
bin/beast-agent.jsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/beast-agent.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
src/main.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/main.jsView on unpkg · L5Package source references weak cryptographic algorithms.
src/agent/mem0.jsView on unpkg · L29A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/agent/searxng.jsView on unpkg · L15