Loopback bidirectional Anthropic/OpenAI API proxy with tool-call validation and multi-provider routing.
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically alters Codex configuration and agent definitions, and installs skills into Claude and Codex directories. Later mutating CLI use can automatically reinstall a newer release and repeat this behavior.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skill.mjsView on unpkg · L8Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-skill.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/delegate-gate/diff-parser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/self-update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/os-keyring.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/secret-file-acl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/winenv.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-tiers.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/accounting-store-schema.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/accounting-store.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dashboard-routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/quota-observation.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/reshaper.jsView on unpkgThis report applies to llm-relay@0.57.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L43Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L43A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/delegate-gate/diff-parser.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/self-update.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/os-keyring.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/secret-file-acl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/winenv.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/sync-tiers.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/accounting-store-schema.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/accounting-store.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/backend.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dashboard-routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/quota-observation.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/reshaper.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skill.mjsView on unpkg · L8Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-skill.mjsView on unpkg