Proactive cognitive AI assistant with Feishu/WeChat integration — learns user interests, pushes cross-domain insights, evolves skills, self-corrects. 40+ LLM providers, runs on cloud/desktop/Android.
LPM blocks this version under the AI-agent control-surface policy. Install-time code mutates the user's broad AI-agent skills directory without an explicit user command. It also fetches and installs a remote skill bundle via npx.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib-BzmkYLE-.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/lib-BzmkYLE-.jsView on unpkg · L426Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-APrZoXsA.jsView on unpkg · L911Package source references dynamic require/import behavior.
dist/control-ui/assets/index-APrZoXsA.jsView on unpkg · L912Package ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lancedb-runtime-Dg2oHA5N.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/skill-scanner-DKAsyxUz.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/control-ui/assets/anthropic-AR11k_nN.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/control-ui/assets/openai-BR_xAflc.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L1104Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-APrZoXsA.jsView on unpkg · L911Package source references dynamic require/import behavior.
dist/control-ui/assets/index-APrZoXsA.jsView on unpkg · L912Package ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lancedb-runtime-Dg2oHA5N.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/skill-scanner-DKAsyxUz.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/control-ui/assets/anthropic-AR11k_nN.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/control-ui/assets/openai-BR_xAflc.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/lib-BzmkYLE-.jsView on unpkg · L426Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib-BzmkYLE-.jsView on unpkg