Connect local AI coding agents (Claude, Codex, Gemini, Qwen, DeepSeek, Cursor, OpenCode, Pi, OpenHuman, Reasonix) to the Grix scheduling platform. Also serves as an OpenClaw plugin for Grix channel transport.
LPM treats this as warn-only first-party agent extension lifecycle risk. Postinstall persists a Grix upgrade guardian under ~/.grix/bin. At OpenClaw plugin runtime, registered tools can download and install a persona into ~/.openclaw after an explicit tool workflow; no install-time exfiltration or foreign control-surface mutation was confirmed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/adapter/claude/claude-adapter.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L26Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/adapter/claude/claude-adapter.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.3.4.tgzView on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1