Local agent for Orquesta - connects your VM to the Orquesta dashboard
When the agent is connected, server-dispatched content can cause it to download and execute a shell script. In daemon mode it also periodically force-updates its global package installation, using passwordless sudo when available.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/ui/onboarding.jsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/ui/onboarding.jsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/index.jsView on unpkg · L171A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L15Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/supabase.jsView on unpkg · L1Source downloads or fetches remote code and executes it.
dist/sudosudo.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/sudosudo.jsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/init.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/generate-manifest.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/hook.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/ui/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/build-binaries.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/coordination.jsView on unpkgThis report applies to orquesta-agent@0.2.246.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L15A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L15Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L1209Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L15Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18Source downloads or fetches remote code and executes it.
dist/sudosudo.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/sudosudo.jsView on unpkgManifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/init.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/generate-manifest.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/hook.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/ui/server.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/build-binaries.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/daemon.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/coordination.jsView on unpkgPackage source references child process execution.
dist/ui/onboarding.jsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/ui/onboarding.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L15A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/index.jsView on unpkg · L171A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L15This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L15A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L15Package source invokes a package manager install command at runtime.
dist/index.jsView on unpkg · L1209Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/supabase.jsView on unpkg · L1