Engine 7 — 给助手一个家 / A home for your AI assistant
When the engine runs, it automatically sends persistent host and usage telemetry to an external default endpoint. The endpoint may subsequently redirect reporting to any HTTPS URL.
Package source references child process execution.
dist/engine-startup.mjsView on unpkg · L389Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjsView on unpkg · L265Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/engine-startup.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/engine-startup.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/engine-startup.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/engine-startup.mjsView on unpkg · L265Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjsView on unpkg · L36Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/engine7.cmdView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.jsView on unpkgThis report applies to engine7@7.1.116.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/cli.mjsView on unpkg · L36Package source references child process execution.
dist/engine-startup.mjsView on unpkg · L389Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjsView on unpkg · L265Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/engine-startup.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/engine-startup.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/engine-startup.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/engine-startup.mjsView on unpkg · L265Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjsView on unpkg · L36Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/engine7.cmdView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjsView on unpkg · L36Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/cli.mjsView on unpkg · L36