1Source sends the broad process environment to a literal external destination.
L1: import{createRequire as Xl}from"node:module";var Gl=Object.create;var{getPrototypeOf:Jl,defineProperty:jM,getOwnPropertyNames:Hl}=Object;var Kl=Object.prototype.hasOwnProperty;func...
L2: `)}displayWidth(A){return aW(A).length}styleTitle(A){return A}styleUsage(A){return A.split(" ").map((B)=>{if(B==="[options]")return this.styleOptionText(B);if(B==="[command]")retur...
...
L12: (Did you mean one of ${I.join(", ")}?)`;if(I.length===1)return`
L13: (Did you mean ${I[0]}?)`;return""}bl.suggestSimilar=xl});var EV=tB((il)=>{var hl=XQ("node:events").EventEmitter,kM=XQ("node:child_process"),_0=XQ("node:path"),g9=XQ("node:fs"),UQ=X...
L14: - specify the name in Command constructor or using .name()`);if(B=B||{},B.isDef
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/cli.jsView on unpkg · L1 •matchType = previous_version_dangerous_delta
matchedPackage = min-agent@3.10.2609250718
matchedIdentity = npm:bWluLWFnZW50:3.10.2609250718
similarity = 0.500
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkg 12(Did you mean one of ${I.join(", ")}?)`;if(I.length===1)return`
L13: (Did you mean ${I[0]}?)`;return""}bl.suggestSimilar=xl});var EV=tB((il)=>{var hl=XQ("node:events").EventEmitter,kM=XQ("node:child_process"),_0=XQ("node:path"),g9=XQ("node:fs"),UQ=X...
L14: - specify the name in Command constructor or using .name()`);if(B=B||{},B.isDefault)this._defaultCommandName=A._name;if(B.noHelp||B.hidden)A._hidden=!0;return this._registerCommand...
15Expecting one of '${Q.join("', '")}'`);if(this._lifeCycleHooks[A])this._lifeCycleHooks[A].push(B);else this._lifeCycleHooks[A]=[B];return this}exitOverride(A){if(A)this._exitCallba...
L16: - already used by option '${B.flags}'`)}this._initOptionGroup(A),this.options.push(A)}_registerCommand(A){let B=(I)=>{return[I.name()].concat(I.aliases())},Q=B(A).find((I)=>this._...
L17: - either make a new Command for each call to parse, or stop storing options as properties`);this._name=this._savedState._name,this._scriptPath=null,this.rawArgs=[],this._optionValu...
25Expecting one of '${Q.join("', '")}'`);let I=`${A}Help`;return this.on(I,(E)=>{let g;if(typeof B==="function")g=B({error:E.error,command:E.command});else g=B;if(g)E.write(`${g}
L26: `)}),this}_outputHelpIfRequested(A){let B=this._getHelpOption();if(B&&A.find((I)=>B.is(I)))this.outputHelp(),this._exit(0,"commander.helpDisplayed","(outputHelp)")}}function IV(A){...
L27: `),Q=WV().map((E)=>`(subpath ${$V(YQ.resolve(E))})`).join(`
...
L39: `}function fV(){if(q8("/usr/bin/bwrap"))return"/usr/bin/bwrap";return"/usr/local/bin/bwrap"}function jV(A,B,Q){let I=["--die-with-parent","--ro-bind","/","/","--dev","/dev","--proc...
L40: ${NV}`:XV,G}function eG(A){return A==="off"?"未隔离":A==="strict"?"严格隔离":"工作区隔离"}function SV(A){return A==="deny"?"禁止联网":"允许联网"}function A3(A=ZE()){return`${eG(A.mode)},
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L25 24`),this._exit(0,"commander.version",A)}),this}description(A,B){if(A===void 0&&B===void 0)return this._description;if(this._description=A,B)this._argsDescription=B;return this}summa...
L25: Expecting one of '${Q.join("', '")}'`);let I=`${A}Help`;return this.on(I,(E)=>{let g;if(typeof B==="function")g=B({error:E.error,command:E.command});else g=B;if(g)E.write(`${g}
L26: `)}),this}_outputHelpIfRequested(A){let B=this._getHelpOption();if(B&&A.find((I)=>B.is(I)))this.outputHelp(),this._exit(0,"commander.helpDisplayed","(outputHelp)")}}function IV(A){...
L27: `),Q=WV().map((E)=>`(subpath ${$V(YQ.resolve(E))})`).join(`
...
L39: `}function fV(){if(q8("/usr/bin/bwrap"))return"/usr/bin/bwrap";return"/usr/local/bin/bwrap"}function jV(A,B,Q){let I=["--die-with-parent","--ro-bind","/","/","--dev",
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L24 24Trigger-reachable command-output exfiltration chain: manifest.bin -> bin/min-agent.js -> dist/cli.js
L24: `),this._exit(0,"commander.version",A)}),this}description(A,B){if(A===void 0&&B===void 0)return this._description;if(this._description=A,B)this._argsDescription=B;return this}summa...
L25: Expecting one of '${Q.join("', '")}'`);let I=`${A}Help`;return this.on(I,(E)=>{let g;if(typeof B==="function")g=B({error:E.error,command:E.command});else g=B;if(g)E.write(`${g}
L26: `)}),this}_outputHelpIfRequested(A){let B=this._getHelpOption();if(B&&A.find((I)=>B.is(I)))this.outputHelp(),this._exit(0,"commander.helpDisplayed","(outputHelp)")}}function IV(A){...
L27: `),Q=WV().map((E)=>`(subpath ${$V(YQ.resolve(E))})`).join(`
...
L39: `}function fV(){if(q8("/usr/bin/bwrap"))return"/usr/bin/bwrap";re
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L24 •matchType = normalized_sha256
matchedPackage = min-agent@2.0.0
matchedPath = dist/cli.js
matchedIdentity = npm:bWluLWFnZW50:2.0.0
similarity = 1.000
summary = normalized source hash matched finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkg •matchType = malicious_source_fingerprint_signature
signature = 007d849e43602ff3
signatureType = suspicious_hashes
sourceLabel = final_verdict:malicious
matchedPackage = min-agent@2.0.0
matchedPath = dist/cli.js
matchedIdentity = npm:bWluLWFnZW50:2.0.0
similarity = 1.000
shingleOverlap = 1
summary = package final verdict is malicious
HighKnown Malware Source Fingerprint Signature
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkg 101`)});var p_={};eB(p_,{runWriteConfig:()=>Ws});async function Ws(A){let B=[],Q=!0;if(A.sandbox!==void 0||A.network!==void 0){let I=r9({positionals:[],flagMode:A.sandbox,flagNetwork:...
L102: `)),!Q)process.exitCode=1}var n_=v(()=>{A$();B$();Q$();I$()});function B6(A,B,Q){let I=A==="openai"?"openai":A==="ollama"?"ollama":Vs(B)??"provider";return Ps(I,Q)}function Q6(A){l...
L103:
MediumDynamic Require
Package source references dynamic require/import behavior.
dist/cli.jsView on unpkg · L101