Ozaiya agent daemon - server management and terminal
When the Ozaiya daemon starts, it copies local Claude, Codex, and Gemini session credentials into provider records and includes those records in daemon state sent to the configured server. The server host defaults to api.ozaiya.com and can be replaced by OZAIYA_SERVER_URL with no allowlist, so the tokens are not bound to Anthropic, OpenAI, or Google.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-8lHUhZM0.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/setupOfflineReconnection-CsNUDUk9.cjsView on unpkg · L2Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/api-CtgNkRPZ.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
bin/ozaiya-local.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-DRfiB6ad.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-Cpsmzffp.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-yrkI9YJA.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-isqO86cA.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_version_utils.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-DU4G79VF.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runCodex-Btx_QtPi.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/env-wrapper.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-B9S56sRQ.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-DpZga4DZ.mjsView on unpkgThis report applies to ozaiya-cli@0.11.25.
See version security history for other recorded verdicts.
Evidence last updated: .
Source dynamically best-effort loads a bundled native addon.
dist/api-CtgNkRPZ.cjsView on unpkg · L371Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/api-CtgNkRPZ.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-CtgNkRPZ.cjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Package source references weak cryptographic algorithms.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L101Package source references dynamic require/import behavior.
dist/setupOfflineReconnection-CsNUDUk9.cjsView on unpkg · L2Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/api-CtgNkRPZ.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
bin/ozaiya-local.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-DRfiB6ad.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-Cpsmzffp.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-yrkI9YJA.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-isqO86cA.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_version_utils.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-DU4G79VF.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runCodex-Btx_QtPi.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/env-wrapper.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-B9S56sRQ.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-DpZga4DZ.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-8lHUhZM0.cjsView on unpkgSource dynamically best-effort loads a bundled native addon.
dist/api-CtgNkRPZ.cjsView on unpkg · L371Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/api-CtgNkRPZ.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-CtgNkRPZ.cjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/api-CtgNkRPZ.cjsView on unpkg · L2Package source references weak cryptographic algorithms.
dist/api-CtgNkRPZ.cjsView on unpkg · L2