NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
Installation automatically downloads an opaque native executable, stores it outside the package, and executes its install command. The payload is not integrity-pinned and its behavior cannot be verified from this snapshot.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook automatically starts the downloader.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgIt downloads a native binary from GitHub Release URLs, including an unpinned latest release.
bin.jsView on unpkg · L98The only validation is a minimum size check before the binary is written and executed with install.
bin.jsView on unpkg · L123This report applies to nur-cli@0.32.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31The postinstall hook automatically starts the downloader.
package.jsonView on unpkg · L30It downloads a native binary from GitHub Release URLs, including an unpinned latest release.
bin.jsView on unpkg · L98The only validation is a minimum size check before the binary is written and executed with install.
bin.jsView on unpkg · L123Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg