用微信,遥控你自己电脑上的 `Claude Code` 和 `Codex CLI`。
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/server/cli.jsView on unpkg · L22A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/server/cli.jsView on unpkgPackage source references child process execution.
dist/server/cli.jsView on unpkg · L2782Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/server/cli.jsView on unpkg · L22Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/cli.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/server/cli.jsView on unpkg · L22Package source references weak cryptographic algorithms.
dist/server/cli.jsView on unpkg · L22A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/mcp/mediaServer.jsView on unpkg · L94Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp/mediaServer.jsView on unpkg · L126Package ships high-entropy non-source blobs.
dist/web/assets/bootstrap-icons-mSm7cUeB.woff2View on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/server/cli.jsView on unpkg · L22Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/server/cli.jsView on unpkg · L22Source writes installer persistence such as shell profile or service configuration.
dist/server/cli.jsView on unpkg · L22Package source references weak cryptographic algorithms.
dist/server/cli.jsView on unpkg · L22A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/server/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/server/cli.jsView on unpkgPackage ships high-entropy non-source blobs.
dist/web/assets/bootstrap-icons-mSm7cUeB.woff2View on unpkgPackage source references child process execution.
dist/server/cli.jsView on unpkg · L2782A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/mcp/mediaServer.jsView on unpkg · L94Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp/mediaServer.jsView on unpkg · L126