Local AI gateway and OpenAI-compatible API router for AI coding tools and 40+ providers
The install hook installs additional runtime dependencies under the user's PolyRouter data directory. A bundled, separately installed browser connector can import ChatGPT/OpenAI cookies to the local gateway, and the app contains opt-in MITM capability for AI-tool traffic.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution with blocking evidence.
cli.jsView on unpkg · L773Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3Source combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgThis report applies to polyrouter@1.0.17.
See version security history for other recorded verdicts.
Evidence last updated: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution with blocking evidence.
cli.jsView on unpkg · L773A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkg · L2This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3Source combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1