Personal AI assistant powered by Pi, Antigravity, AI-E, Claude, Claude E, Codex, Codex App, Cursor, Grok, Kiro, OpenCode, and Copilot — Web, Terminal, Telegram, and Discord interfaces with 107 built-in skills
Installing the package runs an automatic lifecycle hook that fetches and executes remote shell code. It also installs global tools and imports unpinned remote skills into the package's active skill area.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/postinstall.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/bin/commands/launchd.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/launchd.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/commands/doctor.jsView on unpkg · L619Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/doctor.jsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bin/commands/skill.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/MilkdownWysiwygEditor-DanGAZL5.jsView on unpkg · L142Package source invokes a package manager install command at runtime.
dist/bin/commands/mcp.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/commands/clone.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-guard.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/capability-probe-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/routes/quota.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/chat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-distribution.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-reset.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/quota-copilot.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/bin/commands/launchd.jsView on unpkg · L9Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L58Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bin/commands/skill.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/MilkdownWysiwygEditor-DanGAZL5.jsView on unpkg · L142Package source invokes a package manager install command at runtime.
dist/bin/commands/mcp.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/commands/clone.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-guard.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/service.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/capability-probe-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/routes/quota.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/chat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/dashboard.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-distribution.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/mcp/skills-reset.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib/quota-copilot.jsView on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/postinstall.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/bin/commands/launchd.jsView on unpkg · L9A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/bin/commands/launchd.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/launchd.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/commands/doctor.jsView on unpkg · L619Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/commands/doctor.jsView on unpkg