Pi-native UES coding-agent runtime with adaptive stability, Turbo Fast Path, durable verification, managed services, and weak-model orchestration
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkgThis report applies to opencode-agent-skill@15.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkg