BLUN CLI - your own AI agent with a Telegram channel. Get it done. With BLUN.
A normal CLI launch can register and repeatedly beacon runtime metadata to a hard-coded private-address hub when Mnemo is enabled without its own URL. The behavior is automatic and not part of the install hook.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Package source references a known benign dynamic code generation pattern.
telegram-plugin/dist/noise.mjsView on unpkg · L166Package source references dynamic require/import behavior.
bin/cognitive-state-store.cjsView on unpkg · L2Package source executes code through a VM context API.
scripts/check-mcp-startup-wait-budget.jsView on unpkg · L7Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/release-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/cytoscape.esm-nFXppDBa.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-runtime.jsView on unpkgThis report applies to blun-king-cli@9.1.519.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Package source references a known benign dynamic code generation pattern.
telegram-plugin/dist/noise.mjsView on unpkg · L166Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/release-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/cytoscape.esm-nFXppDBa.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-runtime.jsView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Package source references dynamic require/import behavior.
Package source executes code through a VM context API.
scripts/check-mcp-startup-wait-budget.jsView on unpkg · L7Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4