Connect local AI coding agents (Claude, Codex, Gemini, Qwen, DeepSeek, Cursor, OpenCode, Pi, OpenHuman, Reasonix) to the Grix scheduling platform. Also serves as an OpenClaw plugin for Grix channel transport.
LPM treats this as warn-only first-party agent extension lifecycle risk. Install overwrites package-owned Grix upgrade helpers. At runtime, the OpenClaw plugin can alter OpenClaw’s provider/default model and download persona content into its workspaces.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/core/installer/npm-registry.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/adapter/claude/claude-adapter.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/adapter/claude/claude-adapter.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.1.0.tgzView on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/core/installer/npm-registry.jsView on unpkg