BLUN CLI - your own AI agent with a Telegram channel. Get it done. With BLUN.
Static analysis completed at 97.0% confidence. No malicious behavior was detected; 33 low-signal pattern(s) were surfaced and cleared.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-lease.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
telegram-plugin/dist/mcp-server.mjsView on unpkg · L168Package source references dynamic require/import behavior.
bin/agentspine-king-worker-host.mjsView on unpkg · L47Package source executes code through a VM context API.
bin/verify-agent-behavior.cjsView on unpkg · L14Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L5Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/language_gateway.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/check-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/managed-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/scripts/run-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/peer-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/sqlite-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/node-version.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/chunk-5RXB4S5H-BfZa4yDH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/chunk-5RXB4S5H-neG70kZx.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/diagram-Q27KOJAE-D1mYQ_cI.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/diagram-Q27KOJAE-hy_T73PK.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-runtime.jsView on unpkgThis report applies to blun-king-cli@9.1.600.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Package source references a known benign dynamic code generation pattern.
telegram-plugin/dist/mcp-server.mjsView on unpkg · L168Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
telegram-plugin/dist/bridge.mjsView on unpkg · L5Package ships native binary artifacts.
native/darwin/prebuilds/darwin-x64/darwin-modifiers.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
standard-tools/language-guard/language_gateway.pyView on unpkgPackage ships high-entropy non-source blobs.
dist-web/vis/index.html.gzView on unpkgPackage ships compressed or archive-like blobs.
dist-web/vis/index.html.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
blun.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
blun.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
agent-spine-plugin/scripts/check-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/managed-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/scripts/run-checks.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/peer-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
agent-spine-plugin/src/lib/sqlite-transport.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/node-version.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/chunk-5RXB4S5H-BfZa4yDH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/chunk-5RXB4S5H-neG70kZx.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/diagram-Q27KOJAE-D1mYQ_cI.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-web/assets/diagram-Q27KOJAE-hy_T73PK.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launcher-runtime.jsView on unpkgPackage source references child process execution.
bin/update-lease.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/update-lease.jsView on unpkgPackage source references dynamic require/import behavior.
bin/agentspine-king-worker-host.mjsView on unpkg · L47Package source executes code through a VM context API.
bin/verify-agent-behavior.cjsView on unpkg · L14