Connect local AI coding agents (Claude, Codex, Gemini, Qwen, DeepSeek, Cursor, OpenCode, Pi, OpenHuman, Reasonix) to the Grix scheduling platform. Also serves as an OpenClaw plugin for Grix channel transport.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically writes executable guardian helpers outside the package. The service's upgrade and rollback path can reinstall the same package globally.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/adapter/acp/acp-adapter.js#virtual:normalized:round1View on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L27A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/adapter/codex/codex-bridge.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/core/proxy/hermes-profile-relay.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/assets/dsh-bridge/grix-dsh-bridge-4.6.5.tgzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/adapter/acp/acp-adapter.js#virtual:normalized:round1View on unpkgPackage source references child process execution.
openclaw-plugin/index.jsView on unpkg · L2312Package source references dynamic require/import behavior.
dist/core/mcp/internal-api-server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/core/proxy/crypto/certificate.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core/upgrade/upgrade-checker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/core/provider-quota/kiro.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/core/installer/npm-registry.jsView on unpkg · L1