Local x402-paying proxy + MCP server for openzoo.fun — point any OpenAI-compatible harness (Cursor, Claude Code, aider, SDKs) at localhost and it pays per call from a local burner wallet. Solana and Base rails live; Robinhood experimental.
LPM flags this version as an AI-agent control-surface risk. The explicit Cursor takeover feature redirects vendor and agent hosts to a local impersonation server. It forges paid membership state and weakens certificate validation to bypass vendor controls.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/claude-zoo.jsView on unpkg · L50Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
lib/worktree.mjsView on unpkg · L130A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/aoe.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/cursorbackend.jsView on unpkgThis report applies to openzoo@0.50.100.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/claude-zoo.jsView on unpkg · L50A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/aoe.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/cursorbackend.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
lib/worktree.mjsView on unpkg · L130