Omnirush — free daily tokens for the most powerful coding model on earth.
Static analysis completed at 72.0% confidence. No malicious behavior was detected; 18 low-signal pattern(s) were surfaced and cleared.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L11Package source references a known benign dynamic code generation pattern.
assets/extensions/omnirush/mcp-client.bundle.jsView on unpkg · L2953Package source references dynamic require/import behavior.
assets/extensions/omnirush/voice/pvrecorder-worker.cjsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/bin.js#virtual:normalized:round1View on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
src/bin.js#virtual:normalized:round1View on unpkg · L17A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
src/bin.js#virtual:normalized:round1View on unpkg · L17Package ships non-JavaScript build or shell helper files.
scripts/package.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/engine-messages.ts#virtual:normalized:round1View on unpkgThis report applies to omnirush@0.10.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18Package source references a known benign dynamic code generation pattern.
assets/extensions/omnirush/mcp-client.bundle.jsView on unpkg · L2953A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/bin.js#virtual:normalized:round1View on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Package ships non-JavaScript build or shell helper files.
scripts/package.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/engine-messages.ts#virtual:normalized:round1View on unpkgPackage source references child process execution.
scripts/postinstall.jsView on unpkg · L11Package source references dynamic require/import behavior.
assets/extensions/omnirush/voice/pvrecorder-worker.cjsView on unpkg · L6A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
src/bin.js#virtual:normalized:round1View on unpkg · L17