CiCy - AI-powered operating system browser
Running the package launcher or its sidecar bootstrap can download and execute remote runtime artifacts. These writes and executions are not performed by an npm install lifecycle hook.
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgThis report applies to cicy-desktop@2.1.328.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26