Core AI chat agent with multi-agent architecture, ReAct pattern, and modular tool system powered by Gemini
An explicitly enabled vector knowledge-base feature submits runtime queries to a package-controlled Upstash endpoint using embedded fallback credentials. This is a credential-exposure and query-privacy risk, not confirmed malware.
Package source references child process execution.
dist/index.native.jsView on unpkg · L675A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.native.jsView on unpkg · L675Source reaches cloud instance metadata or link-local credential endpoints.
dist/index.native.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.native.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.native.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgPackage source references child process execution.
dist/index.native.jsView on unpkg · L675A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.native.jsView on unpkg · L675Source reaches cloud instance metadata or link-local credential endpoints.
dist/index.native.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.native.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.native.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg