Local AI gateway and OpenAI-compatible API router for AI coding tools and 40+ providers
No confirmed attack surface was established from the inspected source. Required clean citation coverage cannot fit the output limit.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/src/mitm/server.jsView on unpkg · L24Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24Package source references dynamic code evaluation.
app/node_modules/@emnapi/runtime/dist/emnapi.cjs.min.jsView on unpkg · L1Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
app/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/tray/autostart.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
app/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source passes code obtained from a remote response into a dynamic execution sink.
app/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/node_modules/next/dist/build/next-config-ts/transpile-config.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/sqliteRuntime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/api/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
app/node_modules/@next/env/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/xaiVideo.jsView on unpkgThis report applies to polyrouter@1.0.16.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
app/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39Source combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
app/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source passes code obtained from a remote response into a dynamic execution sink.
app/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/node_modules/next/dist/build/next-config-ts/transpile-config.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
hooks/sqliteRuntime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/api/client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
app/node_modules/@next/env/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/xaiVideo.jsView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/src/mitm/server.jsView on unpkg · L24Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24Package source references dynamic code evaluation.
app/node_modules/@emnapi/runtime/dist/emnapi.cjs.min.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/tray/autostart.jsView on unpkg