Personal AI assistant powered by Pi, Antigravity, AI-E, Claude, Claude E, Codex, Codex App, Cursor, Grok, Kiro, OpenCode, and Copilot — Web, Terminal, Telegram, and Discord interfaces with 107 built-in skills
`npm postinstall` performs unprompted environment setup and installs external tools. It downloads and executes vendor scripts for Claude and uv, and globally installs an MCP server. No confirmed credential theft, hidden payload, or default foreign AI-client configuration takeover was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Package source invokes a package manager install command at runtime.
dist/bin/postinstall.jsView on unpkg · L19Package source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/bin/commands/service.jsView on unpkg · L9A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lib/quota-copilot.jsView on unpkg · L7Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/chunk-NNHCCRGN-D69GtSOc.jsView on unpkg · L46Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgPackage ships high-entropy non-source blobs.
public/dist/assets/KaTeX_Script-Regular-D3wIWfF6.woff2View on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
public/dist/assets/chunk-NNHCCRGN-D69GtSOc.jsView on unpkg · L46Package ships non-JavaScript build or shell helper files.
scripts/check-deps-online.shView on unpkgPackage ships high-entropy non-source blobs.
public/dist/assets/KaTeX_Script-Regular-D3wIWfF6.woff2View on unpkgPackage source references child process execution.
dist/bin/postinstall.jsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/postinstall.jsView on unpkg · L5Package source invokes a package manager install command at runtime.
dist/bin/postinstall.jsView on unpkg · L19Package source references a known benign dynamic code generation pattern.
dist/src/browser/adaptive-fetch/defuddle-extractor.jsView on unpkg · L98Package source references dynamic require/import behavior.
dist/src/agent/jwc-runtime.jsView on unpkg · L31Package source references weak cryptographic algorithms.
dist/src/ide/diff.jsView on unpkg · L7Source writes installer persistence such as shell profile or service configuration.
dist/bin/commands/service.jsView on unpkg · L9A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/lib/quota-copilot.jsView on unpkg · L7