Proactive cognitive AI assistant with Feishu/WeChat integration — learns user interests, pushes cross-domain insights, evolves skills, self-corrects. 40+ LLM providers, runs on cloud/desktop/Android.
LPM flags this version as an AI-agent control-surface risk. The npm postinstall hook automatically installs external skills into a shared AI-agent control surface without affirmative consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/resolve-B-YGj7MS.jsView on unpkg · L3Package source references a known benign dynamic code generation pattern.
dist/extensions/diffs/node_modules/playwright-core/lib/generated/utilityScriptSource.js#virtual:normalized:round1View on unpkg · L30Package source references dynamic require/import behavior.
dist/git-commit-C0NqDaJx.jsView on unpkg · L88Package source references weak cryptographic algorithms.
dist/send-media-BCm-tPYM.jsView on unpkg · L12A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/diffs/node_modules/playwright-core/lib/utilsBundleImpl/index.jsView on unpkg · L4Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-Ua-cFlP6.jsView on unpkg · L923Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-DBa1TeO8.jsView on unpkg · L32Package ships native binary artifacts.
dist/extensions/kindle-portal/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.17.3View on unpkgPackage ships WebAssembly modules.
dist/extensions/diffs/node_modules/shiki/dist/onig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/diffs/node_modules/diff/dist/diff.min.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-bundled-plugins.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall-bundled-plugins.mjsView on unpkgThis report applies to kaijibot@2026.8.20.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/extensions/diffs/node_modules/playwright-core/lib/utilsBundleImpl/index.jsView on unpkg · L3Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L1104Package source references a known benign dynamic code generation pattern.
dist/extensions/diffs/node_modules/playwright-core/lib/generated/utilityScriptSource.js#virtual:normalized:round1View on unpkg · L30Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-Ua-cFlP6.jsView on unpkg · L923Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/compact-DBa1TeO8.jsView on unpkg · L32Package ships native binary artifacts.
dist/extensions/kindle-portal/node_modules/@img/sharp-libvips-linux-x64/lib/libvips-cpp.so.8.17.3View on unpkgPackage ships WebAssembly modules.
dist/extensions/diffs/node_modules/shiki/dist/onig.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/diffs/node_modules/diff/dist/diff.min.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall-bundled-plugins.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall-bundled-plugins.mjsView on unpkgPackage source references child process execution.
dist/resolve-B-YGj7MS.jsView on unpkg · L3Package source references dynamic require/import behavior.
dist/git-commit-C0NqDaJx.jsView on unpkg · L88Package source references weak cryptographic algorithms.
dist/send-media-BCm-tPYM.jsView on unpkg · L12A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/diffs/node_modules/playwright-core/lib/utilsBundleImpl/index.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/extensions/diffs/node_modules/playwright-core/lib/utilsBundleImpl/index.jsView on unpkg · L3