CoDev — AI Coding Agent Hub. Install, configure, and manage multiple AI coding agents.
After authentication, ordinary `codevhub`, `codevhub claude`, `codex`, `opencode`, and default passthrough invocations start a detached daemon. It reads local third-party agent transcripts and uploads exported content to the package-controlled analysis backend.
Source executes local commands and sends command output to an external endpoint.
dist/index.jsView on unpkg · L496A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L496Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L34228A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L496Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L45719Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L496Source executes local commands and sends command output to an external endpoint.
dist/index.jsView on unpkg · L496A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L496Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L34228A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L496Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L45719Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L496