Orchestrateur universel agents IA multi-modeles via MCP. Inclut le protocole 'Custom-Nickname' pour identifier vos agents avec des surnoms originaux (The Chaos Prophet, Shadow Sniper, etc.), l'isolation mémoire (Private Memory Context) et le support pour
LPM flags this version as an AI-agent control-surface risk. The npm postinstall hook redirects the foreign Hermes agent home into a package-managed directory without consent. This changes the filesystem location used by native Hermes.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lib/InstallHelper.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L10Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/launch.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/overmind_keygen2000.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/verify-install.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/ClaudeRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-dependencies.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launch.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/ClineRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/HermesProfileManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/KiloRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/OpenClawRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/OpenCodeRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/QwenCliRunner.jsView on unpkgThis report applies to overmind-mcp@3.10.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L56Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L56Package ships non-JavaScript build or shell helper files.
bin/launch.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/overmind_keygen2000.pyView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/verify-install.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/ClaudeRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-dependencies.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/setup.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launch.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/ClineRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/HermesProfileManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/KiloRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/OpenClawRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/OpenCodeRunner.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/QwenCliRunner.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/lib/InstallHelper.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L10Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkg