John's Harness: a production agent harness that runs autonomous coding agents as one cooperative swarm.
Installation silently replaces files in installed dependencies and deletes source maps. This changes the consumer's AI-agent runtime before the package is invoked.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L156Package source references dynamic code evaluation.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L10Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L444Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L62Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L62Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L67A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L9Package ships WebAssembly modules.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/model-selection-L7RMwsG-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-4Fgm-yEH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-Di-lyCdh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/model-auth-CX9cPHdC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/bluebubbles.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-BP0viZiL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cerq29sy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cndjtt0g.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/feishu.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/googlechat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/imessage.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1This report applies to johns-harness@2026.9.20.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L62A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L62Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L242Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L242Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L10Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L444Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L62Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L62Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L67A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L9Package ships WebAssembly modules.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/model-selection-L7RMwsG-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-4Fgm-yEH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-Di-lyCdh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/model-auth-CX9cPHdC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/bluebubbles.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-BP0viZiL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cerq29sy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cndjtt0g.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/feishu.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/googlechat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/imessage.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1Package contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L156Package source references dynamic code evaluation.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom-engine.tsView on unpkg · L64Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L62A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L62