BLUN CLI - your own AI agent with a Telegram channel. Get it done. With BLUN.
Normal CLI startup checks for a release and defaults to installing it automatically. The install is global, enables npm lifecycle scripts, and can enter a nested chain because the package depends on itself at another release range.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Package source references a known benign dynamic code generation pattern.
telegram-plugin/dist/noise.mjsView on unpkg · L166Package source references dynamic require/import behavior.
bin/cognitive-state-store.cjsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/release-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/cytoscape.esm-nFXppDBa.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
agent-spine-plugin/scripts/check-install.jsView on unpkgThis report applies to blun-king-cli@9.1.512.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Package source references a known benign dynamic code generation pattern.
telegram-plugin/dist/noise.mjsView on unpkg · L166Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/release-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/cytoscape.esm-nFXppDBa.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
agent-spine-plugin/scripts/check-install.jsView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Package source references dynamic require/import behavior.
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4