CoDev — AI Coding Agent Hub. Install, configure, and manage multiple AI coding agents.
After a user has authenticated, ordinary launches of Claude, Codex, or OpenCode through CoDev trigger a detached background upload. It collects local conversation logs and sends compressed content to package-controlled upload infrastructure without disclosure in the README.
Source executes local commands and sends command output to an external endpoint.
dist/index.jsView on unpkg · L496A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L496Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L32289A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L496Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L42948Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L496Source executes local commands and sends command output to an external endpoint.
dist/index.jsView on unpkg · L496A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L496Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L32289A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L496Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L42948Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L496