John's Harness: a production agent harness that runs autonomous coding agents as one cooperative swarm.
Installing the package executes a postinstall script that overwrites files in resolved installed dependencies and alters mr-memory. This silently changes the consumer's dependency tree.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L155Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L8Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L479Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L55Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L55Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L60A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L9Package ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/signal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chrome-B3GPMnZQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-BH21wuA9.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-CpgjIXNk.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-D8oVqHh2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-RQlOCmEX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/call-CbaJN9rS.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-BnFhV3or.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-CY7PsNpl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-Dira0ZRW.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1This report applies to johns-harness@2026.9.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L55A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L55Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L231Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L231Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/daemon-cli.jsView on unpkg · L8Package source references dynamic require/import behavior.
dist/daemon-cli.jsView on unpkg · L479Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/reply-C5LKjXcC.jsView on unpkg · L55Source appears to send environment or credential material to an external endpoint.
dist/reply-C5LKjXcC.jsView on unpkg · L55Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/plugin-sdk/telegram.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/telegram.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/shared-Cg8lr3fh.jsView on unpkg · L17Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-B247y5Qt.jsView on unpkg · L60A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/plugin-sdk/index.jsView on unpkg · L21A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/restart-BzjDMmkD.jsView on unpkg · L9Package ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/test_model_usage.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/logger-Bj0Xl6pn.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/discord.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/signal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chrome-B3GPMnZQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-BH21wuA9.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-CpgjIXNk.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-D8oVqHh2.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/chrome-RQlOCmEX.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/call-CbaJN9rS.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-BnFhV3or.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-CY7PsNpl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/pi-embedded-helpers-Dira0ZRW.jsView on unpkgHardcoded password in dist/control-ui/assets/es-DHtyqUQZ.js
dist/control-ui/assets/es-DHtyqUQZ.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/zh-CN-BgJ8_lE3.js
dist/control-ui/assets/zh-CN-BgJ8_lE3.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/index-CvRIBzDR.js
dist/control-ui/assets/index-CvRIBzDR.jsView on unpkg · L3Hardcoded password in dist/control-ui/assets/pt-BR-D2dJb9G8.js
dist/control-ui/assets/pt-BR-D2dJb9G8.jsView on unpkg · L1Hardcoded password in dist/control-ui/assets/de-DuUYLvt1.js
dist/control-ui/assets/de-DuUYLvt1.jsView on unpkg · L1Package contains a possible secret pattern.
dist/control-ui/assets/zh-TW-cW5xB87I.jsView on unpkg · L1Package source references child process execution.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-install-plan.shared-6BfiTrDp.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cm_l3W29.jsView on unpkg · L155Package source references weak cryptographic algorithms.
extensions/diffs/src/viewer-assets.tsView on unpkg · L11Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/reply-C5LKjXcC.jsView on unpkg · L55A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/reply-C5LKjXcC.jsView on unpkg · L55