engine7@7.1.117: Suspicious npm security report (Warn) | LPM Firewall
Flagged — allowed with a warning
Allowed by default policy, but 23 finding(s) warrant review before installing.
AI Security Reviewscanned 8d ago · by lpm-firewall-ai No concrete attack was identified. Inspected configuration, workspace reads, authenticated local serving, and diagram rendering support Engine7 functionality.
Static reason
One or more suspicious static signals were detected.; source matched previously finalized malicious package; routed for review; previous stored version diff introduced dangerous source
Trigger
Explicit Engine7 CLI commands, runtime startup, or separate template script execution activate the inspected behavior.
Impact
No malicious installation mutation, covert credential forwarding, or unrelated payload execution was established.
Mechanism
The CLI creates its selected workspace; runtime analysis reads prompt files, while template scripts serve authenticated content or invoke Graphviz.
AI rationale
The inspected source shows package-aligned runtime and user-invoked workspace setup, with no registry-install execution chain. The required agent locations and template scripts do not establish malicious behavior or a concrete unresolved warning.
Decision evidencepublic snapshot AI called this Clean at 88.0% confidence as Benign with low false-positive risk.
Why the final policy warns
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Evidence for AI clean decision
package.json selects the Engine7 CLI and runtime, with no install lifecycle hooks or runtime self-dependency. dist/cli.mjs configures workspace prompt files; setup requires an explicit CLI invocation and builds the selected Engine7 state directory. dist/engine-startup.mjs reads workspace AGENTS.md to calculate memory token usage. dist/main.mjs contains the same workspace memory analysis, without agent configuration mutation at the indicated location. The brainstorming server authenticates requests, defaults to loopback, and confines file serving to its content directory. The graph renderer passes diagram content through standard input to a fixed Graphviz command during explicit script execution. Behavioral surface
Source ChildProcess Crypto DynamicRequire EnvironmentVars
Source & flagged code15 flagged · loading source • matchType = previous_version_dangerous_delta
matchedPackage = engine7@7.1.115
matchedIdentity = npm:ZW5naW5lNw:7.1.115
similarity = 0.769
summary = stored previous version shares package body but lacks this dangerous source file
Critical Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/engine-startup.mjs View on unpkg 384 // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
High Child Process
Package source references child process execution.
dist/engine-startup.mjs View on unpkg · L384 3102 }
L3103: cachedShell = { shell: "powershell.exe", args: ["-NoProfile", "-Command"] };
L3104: return cachedShell;
Findings1 Critical 10 High 6 Medium 6 Low
Critical Previous Version Dangerous Delta dist/engine-startup.mjs
High Child Process dist/engine-startup.mjs
High Shell dist/engine-startup.mjs
High Credential Redirect Persistence dist/main.mjs
High Entrypoint Foreign Package Code Overwrite dist/cli.mjs
High Command Output Exfiltration dist/engine-startup.mjs
High Cross File Remote Execution Context dist/cli.mjs
High Trigger Reachable Persistence dist/cli.mjs
High Semantic Analysis Limited templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1
High Known Malware Source Similarity templates/skills/superpowers/brainstorming/scripts/server.cjs
Affected versions and remediation This report applies to engine7@7.1.117 .
See version security history for other recorded verdicts.
Review the evidence and your use of engine7@7.1.117 before allowing it. Restrict the permissions described in this report. Choose an independently verified alternative or release. This report does not establish that other versions are safe. Evidence last updated: 2026-09-30 07:04:59.489Z (UTC) .
88% Clean
AI assessment confidence
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package metadata npm Maintainers engine7
Version 7.1.117
Latest on npm 7.1.120
Published Sep 30, 2026
License Apache-2.0
Dependencies 21
Integrity verified
Package size 1.90 MB
Files 273
Runtime surface package.json Entrypoints main → dist/main.mjs bin → engine7
Runtime node >=22 os win32, linux, darwin cpu x64, arm64
Artifact 8.79 MB · 273 files
Filesystem
Network
Shell
WebSocket
Supply chain HighEntropyStrings UrlStrings
Manifest No manifest risk signals triggered.
scanned 8 file(s), 5.06 MB of source, external domains: 127.0.0.1, accounts.feishu.cn, accounts.larksuite.com, api.anthropic.com, api.deepinfra.com, api.deepseek.com, api.github.com, api.minimaxi.com, api.moonshot.cn, api.tavily.com, api.x.ai, dashscope.aliyuncs.com, fal.run, github.com, ilinkai.weixin.qq.com, novac2c.cdn.weixin.qq.com, open.bigmodel.cn, open.feishu.cn, primeradiant.com, token-plan.cn-beijing.maas.aliyuncs.com, www.apple.com, www.twinsun.top
260 try {
L261: const raw = JSON.parse(fs.readFileSync(filePath, "utf-8"));
L262: loadHooksFromConfig(raw);
...
L384: // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
L387: function parseHookOutput(stdout) {
L388: const trimmed = stdout.trim();
...
L465: const envVars = {
L466: ...process.env,
L467: CLAUDE_PROJECT_DIR: ctx.workspace
...
L469: const command = hook.command;
High Command Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjs View on unpkg · L260 1 const require=(await import('node:module')).createRequire(import.meta.url)
L2: var __defProp = Object.defineProperty;
Medium Dynamic Require
Package source references dynamic require/import behavior.
dist/engine-startup.mjs View on unpkg · L1 260 try {
L261: const raw = JSON.parse(fs.readFileSync(filePath, "utf-8"));
L262: loadHooksFromConfig(raw);
...
L384: // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
L387: function parseHookOutput(stdout) {
L388: const trimmed = stdout.trim();
...
L465: const envVars = {
L466: ...process.env,
L467: CLAUDE_PROJECT_DIR: ctx.workspace
...
L469: const command = hook.command;
Low Weak Crypto
Package source references weak cryptographic algorithms.
dist/engine-startup.mjs View on unpkg · L260 • Manifest-reachable source resolves another installed package, overwrites its runtime code, and injects package-defined remote behavior.
dist/cli.mjs:
feishu: "https://accounts.feishu.cn",
lark: "https://accounts.larksuite.com"
if (redirectHost) currentBaseUrl = `https://${redirectHost}`;
fs.writeFileSync(credFile, JSON.stringify({ accountId, token, baseUrl, userId }, null, 2), "utf8");
ILINK_BASE_URL = "https://ilinkai.weixin.qq.com";
fs43.writeFileSync(cfgPath, JSON.stringify(raw, null, 2) + "\n", "utf-8");
def.baseUrl = "https://open.bigmodel.cn/api/paas/v4";
def.baseUrl = "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1";
High Entrypoint Foreign Package Code Overwrite
Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjs View on unpkg 31 Cross-file remote execution chain: dist/cli.mjs spawns dist/main.mjs; helper contains network access plus dynamic code execution.
L31: const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
High Cross File Remote Execution Context
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjs View on unpkg · L31 31 Trigger-reachable persistence chain: manifest.bin -> bin/engine7 -> dist/cli.mjs
L31: const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
High Trigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjs View on unpkg · L31 31 const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
Medium Install Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/cli.mjs View on unpkg · L31 • Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/main.mjs:
fs60.writeFileSync(cfgPath, JSON.stringify(raw, null, 2) + "\n", "utf-8");
`Base URL: ${config2.provider.baseUrl}`,
fs3.writeFileSync(dumpPath, [systemStable, systemDynamic].join("\n\n"), "utf-8");
fs3.writeFileSync(path2.join(opts.workspace, ".context-debug.txt"), lines.join("\n") + "\n", "utf-8");
fs7.writeFileSync(outputPath, "", "utf-8");
fs7.writeFileSync(tmp, JSON.stringify(next, null, 2));
fs7.writeFileSync(tmp, JSON.stringify(pendingNotifications, null, 2), "utf8");
if (process.env.CLAUDE_CODE_MAX_RETRIES) {
High Credential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjs View on unpkg • path = bin/engine7.cmd
kind = build_helper
sizeBytes = 42
magicHex = [redacted]
Medium Ships Build Helper
Package ships non-JavaScript build or shell helper files.
bin/engine7.cmd View on unpkg templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1 View file • stage = ast_semantic_analysis; reason = ast_parse_error; limitedFiles = 1
High Semantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1 View on unpkg templates/skills/superpowers/brainstorming/scripts/server.cjs View file • matchType = normalized_sha256
matchedPackage = engine7@7.1.116
matchedPath = [redacted].cjs
matchedIdentity = npm:ZW5naW5lNw:7.1.116
similarity = 1.000
summary = normalized source hash matched finalized malicious source
High Known Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjs View on unpkg templates/skills/superpowers/writing-skills/render-graphs.js View file • matchType = normalized_sha256
matchedPackage = engine7@7.1.116
matchedPath = [redacted]-skills/render-graphs.js
matchedIdentity = npm:ZW5naW5lNw:7.1.116
similarity = 1.000
summary = normalized source hash matched finalized malicious source
High Known Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.js View on unpkg High
Known Malware Source Similarity
templates/skills/superpowers/writing-skills/render-graphs.js
Medium Dynamic Require dist/engine-startup.mjs
Medium Install Persistence dist/cli.mjs
Medium Ships Build Helper bin/engine7.cmd
Medium Structural Risk Force Deep Review
Low Non Install Lifecycle Scripts
Low Weak Crypto dist/engine-startup.mjs
2 signature(s)
Install lifecycle prepublishOnly
Behavioral surface ChildProcess Crypto DynamicRequire EnvironmentVars Filesystem Network Shell WebSocket HighEntropyStrings UrlStrings Manifest: clean
LPM.dev Registry
Source & flagged code15 flagged • matchType = previous_version_dangerous_delta
matchedPackage = engine7@7.1.115
matchedIdentity = npm:ZW5naW5lNw:7.1.115
similarity = 0.769
summary = stored previous version shares package body but lacks this dangerous source file
Critical Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/engine-startup.mjs View on unpkg 384 // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
High Child Process
Package source references child process execution.
dist/engine-startup.mjs View on unpkg · L384 3102 }
L3103: cachedShell = { shell: "powershell.exe", args: ["-NoProfile", "-Command"] };
L3104: return cachedShell;
260 try {
L261: const raw = JSON.parse(fs.readFileSync(filePath, "utf-8"));
L262: loadHooksFromConfig(raw);
...
L384: // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
L387: function parseHookOutput(stdout) {
L388: const trimmed = stdout.trim();
...
L465: const envVars = {
L466: ...process.env,
L467: CLAUDE_PROJECT_DIR: ctx.workspace
...
L469: const command = hook.command;
High Command Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjs View on unpkg · L260 1 const require=(await import('node:module')).createRequire(import.meta.url)
L2: var __defProp = Object.defineProperty;
Medium Dynamic Require
Package source references dynamic require/import behavior.
dist/engine-startup.mjs View on unpkg · L1 260 try {
L261: const raw = JSON.parse(fs.readFileSync(filePath, "utf-8"));
L262: loadHooksFromConfig(raw);
...
L384: // src/hooks/executor.ts
L385: import { spawn } from "child_process";
L386: import { randomUUID } from "node:crypto";
L387: function parseHookOutput(stdout) {
L388: const trimmed = stdout.trim();
...
L465: const envVars = {
L466: ...process.env,
L467: CLAUDE_PROJECT_DIR: ctx.workspace
...
L469: const command = hook.command;
Low Weak Crypto
Package source references weak cryptographic algorithms.
dist/engine-startup.mjs View on unpkg · L260 • Manifest-reachable source resolves another installed package, overwrites its runtime code, and injects package-defined remote behavior.
dist/cli.mjs:
feishu: "https://accounts.feishu.cn",
lark: "https://accounts.larksuite.com"
if (redirectHost) currentBaseUrl = `https://${redirectHost}`;
fs.writeFileSync(credFile, JSON.stringify({ accountId, token, baseUrl, userId }, null, 2), "utf8");
ILINK_BASE_URL = "https://ilinkai.weixin.qq.com";
fs43.writeFileSync(cfgPath, JSON.stringify(raw, null, 2) + "\n", "utf-8");
def.baseUrl = "https://open.bigmodel.cn/api/paas/v4";
def.baseUrl = "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1";
High Entrypoint Foreign Package Code Overwrite
Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjs View on unpkg 31 Cross-file remote execution chain: dist/cli.mjs spawns dist/main.mjs; helper contains network access plus dynamic code execution.
L31: const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
High Cross File Remote Execution Context
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjs View on unpkg · L31 • Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/main.mjs:
fs60.writeFileSync(cfgPath, JSON.stringify(raw, null, 2) + "\n", "utf-8");
`Base URL: ${config2.provider.baseUrl}`,
fs3.writeFileSync(dumpPath, [systemStable, systemDynamic].join("\n\n"), "utf-8");
fs3.writeFileSync(path2.join(opts.workspace, ".context-debug.txt"), lines.join("\n") + "\n", "utf-8");
fs7.writeFileSync(outputPath, "", "utf-8");
fs7.writeFileSync(tmp, JSON.stringify(next, null, 2));
fs7.writeFileSync(tmp, JSON.stringify(pendingNotifications, null, 2), "utf8");
if (process.env.CLAUDE_CODE_MAX_RETRIES) {
High Credential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjs View on unpkg • path = bin/engine7.cmd
kind = build_helper
sizeBytes = 42
magicHex = [redacted]
Medium Ships Build Helper
Package ships non-JavaScript build or shell helper files.
bin/engine7.cmd View on unpkg templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1 View file • stage = ast_semantic_analysis; reason = ast_parse_error; limitedFiles = 1
High Semantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1 View on unpkg templates/skills/superpowers/brainstorming/scripts/server.cjs View file • matchType = normalized_sha256
matchedPackage = engine7@7.1.116
matchedPath = [redacted].cjs
matchedIdentity = npm:ZW5naW5lNw:7.1.116
similarity = 1.000
summary = normalized source hash matched finalized malicious source
High Known Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjs View on unpkg templates/skills/superpowers/writing-skills/render-graphs.js View file • matchType = normalized_sha256
matchedPackage = engine7@7.1.116
matchedPath = [redacted]-skills/render-graphs.js
matchedIdentity = npm:ZW5naW5lNw:7.1.116
similarity = 1.000
summary = normalized source hash matched finalized malicious source
High Known Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.js View on unpkg 31
Trigger-reachable persistence chain: manifest.bin -> bin/engine7 -> dist/cli.mjs
L31: const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
High Trigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjs View on unpkg · L31 31 const url = `${ACCOUNTS_URL[domain]}${REGISTRATION_PATH}`;
L32: const res = await fetch(url, {
L33: method: "POST",
L34: headers: { "Content-Type": "application/x-www-form-urlencoded" },
L35: body: new URLSearchParams(body).toString(),
L36: signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS)
...
L38: if (!res.ok) {
L39: throw new Error(`\u98DE\u4E66\u6CE8\u518C\u63A5\u53E3\u8FD4\u56DE ${res.status}: ${await res.text()}`);
L40: }
...
L184: const timeoutSeconds = options?.timeoutSeconds || 480;
L185: const stateDir = options?.stateDir || path.join(os.homedir?.() || "/tmp", ".engine7");
L186: const onQrCode = options?.onQrCode;
Medium Install Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/cli.mjs View on unpkg · L31