John's Harness: a production agent harness that runs autonomous coding agents as one cooperative swarm.
LPM treats this as warn-only first-party agent extension lifecycle risk. The postinstall adapts the installed mr-memory plugin in place as part of package installation. This is package-owned plugin setup; no concrete malicious attack surface was established.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L11Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L445Package source references dynamic code evaluation.
scripts/check-models-master.mjsView on unpkg · L36Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L157Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L62Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L62Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L67A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L10Package ships WebAssembly modules.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/model-selection-L7RMwsG-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-4Fgm-yEH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-Di-lyCdh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/model-auth-CX9cPHdC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/bluebubbles.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-BP0viZiL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cerq29sy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cndjtt0g.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/feishu.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/googlechat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/imessage.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1This report applies to johns-harness@2026.9.40.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L62A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L62Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L11Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L445Package source references dynamic code evaluation.
scripts/check-models-master.mjsView on unpkg · L36Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L157Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L62Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L62Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L67A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L10Package ships WebAssembly modules.
node_modules/@mariozechner/pi-coding-agent/examples/extensions/doom-overlay/doom/build/doom.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/model-selection-L7RMwsG-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-4Fgm-yEH.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/config-Di-lyCdh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/model-auth-CX9cPHdC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/bluebubbles.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-BP0viZiL.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cerq29sy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/dispatch-Cndjtt0g.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/feishu.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/googlechat.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/imessage.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L62A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L62