Personal AI assistant powered by Pi, Antigravity, AI-E, Claude, Claude E, Codex, Codex App, Cursor, Grok, Kiro, OpenCode, and Copilot — Web, Terminal, Telegram, and Discord interfaces with 107 built-in skills
Installing the package automatically runs a broad setup routine. It downloads and executes remote installers, globally installs tools, and fetches remote skill content into user-controlled home directories.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/postinstall.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/bin/commands/launchd.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/launchd.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/commands/doctor.jsView on unpkg · L619Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bin/commands/skill.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/MilkdownWysiwygEditor-DanGAZL5.jsView on unpkg · L142Package source invokes a package manager install command at runtime.
dist/bin/commands/mcp.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/commands/clone.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/agent/pi-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/capability-probe-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/chat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-distribution.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-reset.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/quota-copilot.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/agent/codex-app-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/acp-client.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/bin/commands/launchd.jsView on unpkg · L9Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L55Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bin/commands/skill.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/MilkdownWysiwygEditor-DanGAZL5.jsView on unpkg · L142Package source invokes a package manager install command at runtime.
dist/bin/commands/mcp.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/commands/clone.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/agent/pi-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/capability-probe-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/chat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-distribution.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-reset.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/quota-copilot.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/agent/codex-app-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/acp-client.jsView on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/postinstall.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/bin/commands/launchd.jsView on unpkg · L9A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/bin/commands/launchd.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/launchd.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/commands/doctor.jsView on unpkg · L619