BLUN CLI - your own AI agent with a Telegram channel. Get it done. With BLUN.
Static analysis flagged 31 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-lease.jsView on unpkgPackage source references shell execution.
agent-spine-plugin/scripts/check-hosts.jsView on unpkg · L7Package source references a known benign dynamic code generation pattern.
telegram-plugin/compat/mcp-server-fa511cd1.mjsView on unpkg · L169Package source references dynamic require/import behavior.
bin/cognitive-state-store.cjsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/check-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/managed-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/runtime-exit-ledger.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/scripts/run-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/peer-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/agent-api-usage-journal.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cognitive-memory-command.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/sqlite-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/node-version.jsView on unpkgThis report applies to blun-king-cli@9.1.587.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Package source references a known benign dynamic code generation pattern.
telegram-plugin/compat/mcp-server-fa511cd1.mjsView on unpkg · L169Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/blun_language_guard.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/check-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/managed-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/runtime-exit-ledger.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/scripts/run-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/peer-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/agent-api-usage-journal.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cognitive-memory-command.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/sqlite-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/node-version.jsView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-lease.jsView on unpkgPackage source references shell execution.
agent-spine-plugin/scripts/check-hosts.jsView on unpkg · L7Package source references dynamic require/import behavior.
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L4