Mergen — the Execution & Security Gateway for AI agents. Deterministic local gate that blocks destructive tool calls in <1ms before they execute, holds risky calls for Slack HITL approval, and keeps a tamper-evident audit trail. Claude Code/Windsurf PreTo
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package contains a possible secret pattern.
dist/commands/connect.jsView on unpkg · L287Package source references child process execution.
dist/intelligence/git-adr-sync.jsView on unpkg · L1Package source references dynamic code evaluation.
dist/intelligence/impl-critic.jsView on unpkg · L25Package source references dynamic require/import behavior.
dist/intelligence/execution-mode.jsView on unpkg · L20Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/commands/setup.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/commands/setup.jsView on unpkg · L955Source appears to send environment or credential material to an external endpoint.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
dist/routes/device-auth-stub.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/intelligence/enterprise-policy-engine.jsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/incident.js#virtual:normalized:round1View on unpkgThis report applies to mergen-server@1.6.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/commands/setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/commands/setup.jsView on unpkg · L2881Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/commands/setup.jsView on unpkg · L1Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/commands/setup.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/commands/setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/commands/setup.jsView on unpkg · L2881A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/setup.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/commands/setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2Package contains a possible secret pattern.
dist/commands/connect.jsView on unpkg · L287Package source references child process execution.
dist/intelligence/git-adr-sync.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/commands/setup.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/commands/setup.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
dist/routes/device-auth-stub.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/intelligence/enterprise-policy-engine.jsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/commands/incident.js#virtual:normalized:round1View on unpkgPackage source references dynamic code evaluation.
dist/intelligence/impl-critic.jsView on unpkg · L25Package source references dynamic require/import behavior.
dist/intelligence/execution-mode.jsView on unpkg · L20A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/commands/setup.jsView on unpkg · L955Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/commands/setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/commands/setup.jsView on unpkg · L2881Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/commands/setup.jsView on unpkg · L1Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/commands/setup.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/commands/setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/commands/setup.jsView on unpkg · L2881A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/intelligence/shadow-digest-cron.jsView on unpkg · L2