Clavue: execution-first AI coding CLI with direct repo tools, provider routing, native workflows, MCP integration, and long-session recovery
On interactive pager startup, the package can fetch an executable and make it executable without a signature or checksum check. The fetched binary is then selected as the pager executable.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/mao-command.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mao-command.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/openai-responses-adapter.jsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/openai-responses-adapter.jsPackage ships native binary artifacts.
dist/native/clavue-pager-darwin-x64View on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/provider-setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/openai-responses-adapter.jsView on unpkg · L75Source reaches cloud instance metadata or link-local credential endpoints.
dist/openai-responses-adapter.jsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/openai-responses-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/openai-responses-adapter.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L79Source appears to send environment or credential material to an external endpoint.
dist/openai-responses-adapter.jsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/openai-responses-adapter.jsPackage ships native binary artifacts.
dist/native/clavue-pager-darwin-x64View on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/provider-setup.jsView on unpkgPackage source references child process execution.
dist/mao-command.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/mao-command.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/openai-responses-adapter.jsView on unpkg · L75Source reaches cloud instance metadata or link-local credential endpoints.
dist/openai-responses-adapter.jsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/openai-responses-adapter.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/openai-responses-adapter.jsView on unpkg