NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
Install and the CLI entry both download an unsigned native binary from GitHub Releases and run it. There is no integrity check, latest is tried first, and redirects are not pinned to GitHub. The opaque nur install step can change the user environment beyond the npm package itself.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpackage.json postinstall runs node bin.js --ensure on every npm install and ignores failure.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgbin.js downloads a native GitHub Releases asset, trying latest first then a version fallback, with no checksum or signature check.
bin.jsView on unpkg · L100The downloaded bytes are written to the user local bin path and marked executable.
bin.jsView on unpkg · L127This report applies to nur-cli@0.30.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31package.json postinstall runs node bin.js --ensure on every npm install and ignores failure.
package.jsonView on unpkg · L30bin.js downloads a native GitHub Releases asset, trying latest first then a version fallback, with no checksum or signature check.
bin.jsView on unpkg · L100The downloaded bytes are written to the user local bin path and marked executable.
bin.jsView on unpkg · L127Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg