Ultra-fast local agent shell for Windows.
At runtime, a failed computer-use driver launch causes the package to fetch and execute a remote installer through a shell. This gives the cua.ai endpoint arbitrary code execution in the user's account.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/beast-agent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/beast-agent.jsView on unpkgPackage source references dynamic require/import behavior.
bin/beast-agent.jsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/main.jsView on unpkg · L5Package source references weak cryptographic algorithms.
src/agent/mem0.jsView on unpkg · L29A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/agent/searxng.jsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/searxng.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
src/agent/store.jsView on unpkgSource downloads or fetches remote code and executes it.
src/agent/tools.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/tools.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/agent/computeruse.jsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/computeruse.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
src/agent/defaulttools/mt5_m15_m5/m15m5.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/fix-electron.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/gittools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mt5bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/bus.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/llm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/memory.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/perception.jsView on unpkgThis report applies to beast-agent@2.44.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/main.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
src/main.jsView on unpkg · L5Package source invokes a package manager install command at runtime.
src/main.jsView on unpkg · L3653Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L43A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/main.jsView on unpkg · L5Manifest-reachable source overwrites another installed package with package-defined remote behavior.
src/agent/store.jsView on unpkgSource downloads or fetches remote code and executes it.
src/agent/tools.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/tools.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/agent/computeruse.jsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/computeruse.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
src/agent/defaulttools/mt5_m15_m5/m15m5.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/fix-electron.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/gittools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mt5bridge.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/bus.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/llm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/memory.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/skills.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/perception.jsView on unpkgPackage source references dynamic require/import behavior.
bin/beast-agent.jsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/beast-agent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/beast-agent.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/main.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
src/main.jsView on unpkg · L5Package source invokes a package manager install command at runtime.
src/main.jsView on unpkg · L3653Package source references weak cryptographic algorithms.
src/agent/mem0.jsView on unpkg · L29A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/agent/searxng.jsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/searxng.jsView on unpkg