A fast, autonomous coding agent for the terminal, with pluggable LLM providers.
Installing the package invokes an external skills-sync command without user interaction. That command can alter an AI-agent skills control surface during npm installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/presentation.tsView on unpkgPackage source references dynamic require/import behavior.
src/tools/presentation.tsView on unpkg · L9Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/mcp/catalog.tsView on unpkg · L39A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/mcp/catalog.tsView on unpkg · L39Source reaches cloud instance metadata or link-local credential endpoints.
src/networkPolicy.tsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/evolve/fitness.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/communication.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/evolve/fitness.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/preview/launchChrome.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/autonomy/autoInstall.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/vscodeBridge.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/capabilities.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/github/exec.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/providers/codexAppServer.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L48Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L48Source reaches cloud instance metadata or link-local credential endpoints.
src/networkPolicy.tsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/evolve/fitness.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/communication.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/evolve/fitness.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/preview/launchChrome.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/autonomy/autoInstall.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/vscodeBridge.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/capabilities.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/github/exec.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/providers/codexAppServer.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.tsView on unpkgPackage source references dynamic require/import behavior.
src/tools/presentation.tsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/presentation.tsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/mcp/catalog.tsView on unpkg · L39A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/mcp/catalog.tsView on unpkg · L39