NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
Installing the npm package automatically fetches a mutable GitHub release binary, stores it in the user home directory, and executes its installer. This gives unreviewed remote native code install-time execution and allows broader machine changes outside the package directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook runs the downloader automatically and suppresses failure.
package.jsonView on unpkg · L30Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgThe hook downloads a release-selected native executable, writes it under the user home directory, then executes its install command.
bin.jsView on unpkg · L100The hook downloads a release-selected native executable, writes it under the user home directory, then executes its install command.
bin.jsView on unpkg · L127This report applies to nur-cli@0.36.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31The postinstall hook runs the downloader automatically and suppresses failure.
package.jsonView on unpkg · L30The hook downloads a release-selected native executable, writes it under the user home directory, then executes its install command.
bin.jsView on unpkg · L100The hook downloads a release-selected native executable, writes it under the user home directory, then executes its install command.
bin.jsView on unpkg · L127Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg