Terminal-native AI agent CLI with bilingual TR/EN UI, multi-agent orchestration, persistent memory, secure tools and messaging integrations.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references dynamic require/import behavior.
bin/natureco.jsView on unpkg · L5Package source references weak cryptographic algorithms.
src/commands/gateway-server.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/tools/cron_create.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/tools/voice_chat.jsView on unpkg · L15Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/utils/channel-runtime.jsView on unpkg · L71A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/utils/channel-runtime.jsView on unpkg · L71Source appears to send environment or credential material to an external endpoint.
src/tools/phone_control_enhanced.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tools/youtube_ac.jsView on unpkg · L4Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
src/commands/migrate.jsView on unpkgPackage source invokes a package manager install command at runtime.
src/commands/update.jsView on unpkg · L137A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/natureco.js#virtual:normalized:round1View on unpkgThis report applies to natureco-cli@6.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tools/youtube_ac.jsView on unpkg · L4Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
src/commands/migrate.jsView on unpkgPackage source invokes a package manager install command at runtime.
src/commands/update.jsView on unpkg · L137A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/natureco.js#virtual:normalized:round1View on unpkgPackage source references dynamic require/import behavior.
bin/natureco.jsView on unpkg · L5Package source references weak cryptographic algorithms.
src/commands/gateway-server.jsView on unpkg · L4Source writes installer persistence such as shell profile or service configuration.
src/tools/cron_create.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/tools/voice_chat.jsView on unpkg · L15Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/utils/channel-runtime.jsView on unpkg · L71A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/utils/channel-runtime.jsView on unpkg · L71