BingoCode - AI-powered coding assistant CLI built on Claude
LPM flags this version as an AI-agent control-surface risk. Installation writes a bundled skill into the user's Claude configuration without an explicit setup command. That skill changes Claude response behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
src/utils/powershell/parser.tsView on unpkg · L1343Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/claude-win.cjsView on unpkgPackage source references weak cryptographic algorithms.
src/utils/plugins/mcpbHandler.tsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/entrypoints/tray-only.tsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/utils/ide.tsView on unpkg · L1354Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.cjsView on unpkg · L2Package ships native binary artifacts.
src/utils/vendor/ripgrep/x64-win32/rg.exeView on unpkgPackage ships non-JavaScript build or shell helper files.
runtime/win_helper.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/components/ValidationErrorsList.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/upstreamproxy/upstreamproxy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/bingocode-win.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/SkillTool/SkillTool.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Package source references child process execution.
bin/claude-win.cjsPackage source references shell execution.
src/utils/imagePaste.tsPackage ships native binary artifacts.
src/utils/vendor/ripgrep/x64-win32/rg.exeView on unpkgPackage ships non-JavaScript build or shell helper files.
runtime/win_helper.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/components/ValidationErrorsList.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/upstreamproxy/upstreamproxy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/bingocode-win.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/SkillTool/SkillTool.tsView on unpkgPackage contains a possible secret pattern.
src/utils/powershell/parser.tsView on unpkg · L1343Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/claude-win.cjsView on unpkgPackage source references weak cryptographic algorithms.
src/utils/plugins/mcpbHandler.tsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/entrypoints/tray-only.tsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/utils/ide.tsView on unpkg · L1354Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.cjsView on unpkg · L2