Engine 7 — 给助手一个家 / A home for your AI assistant
No confirmed attack surface was identified. Inspected configuration behavior concerns Engine 7's own workspace, and helper commands support local visualization.
Package source references child process execution.
dist/engine-startup.mjsView on unpkg · L384Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjsView on unpkg · L260This report applies to engine7@7.1.118.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/engine-startup.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/engine-startup.mjsView on unpkg · L260Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjsView on unpkg · L31A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjsView on unpkg · L31Source writes installer persistence such as shell profile or service configuration.
dist/cli.mjsView on unpkg · L31Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/engine7.cmdView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.jsView on unpkgPackage source references child process execution.
dist/engine-startup.mjsView on unpkg · L384Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/engine-startup.mjsView on unpkg · L260Package source references dynamic require/import behavior.
dist/engine-startup.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/engine-startup.mjsView on unpkg · L260Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.mjsView on unpkg · L31Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/main.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/engine7.cmdView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
templates/skills/superpowers/brainstorming/scripts/server.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/brainstorming/scripts/server.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
templates/skills/superpowers/writing-skills/render-graphs.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.mjsView on unpkg · L31Source writes installer persistence such as shell profile or service configuration.
dist/cli.mjsView on unpkg · L31