CiCy - AI-powered operating system browser
At application runtime, the package can download native components and launch them as detached local processes. It also configures application login autostart by default.
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/backends/sidecar-ipc.jsView on unpkgThis report applies to cicy-desktop@2.1.325.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/backends/sidecar-ipc.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26