Local AI gateway and OpenAI-compatible API router for AI coding tools and 40+ providers
On installation, the package creates a user-writable runtime directory and runs npm to obtain additional code, including a native SQLite module and a tray package. This is an automatic supply-chain expansion outside the package tarball.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution with blocking evidence.
cli.jsView on unpkg · L773Package source references dynamic code evaluation.
app/node_modules/next/dist/compiled/browserslist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
app/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3Source combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
app/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source contains an obfuscated payload loader that reconstructs and executes hidden code.
app/node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L21391Source passes code obtained from a remote response into a dynamic execution sink.
app/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Native or WebAssembly artifact printable strings contain known collector or webhook infrastructure.
app/node_modules/@ngrok/ngrok-linux-x64-gnu/ngrok.linux-x64-gnu.nodeView on unpkgPackage ships native binary artifacts.
app/node_modules/@ngrok/ngrok-linux-x64-gnu/ngrok.linux-x64-gnu.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/node_modules/next/dist/build/next-config-ts/transpile-config.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
app/node_modules/@next/env/dist/index.jsView on unpkgThis report applies to polyrouter@1.0.19.
See version security history for other recorded verdicts.
Evidence last updated: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21Package source references dynamic require/import behavior.
app/server.jsView on unpkg · L1Package source references weak cryptographic algorithms.
app/node_modules/next/dist/compiled/@edge-runtime/primitives/load.jsView on unpkg · L39Source combines credential-like environment material and outbound requests; review data flow before blocking.
app/src/realtime/runtime.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
app/node_modules/next/dist/next-devtools/server/launch-editor.js#virtual:normalized:round1View on unpkg · L50Source contains an obfuscated payload loader that reconstructs and executes hidden code.
app/node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L21391Source passes code obtained from a remote response into a dynamic execution sink.
app/node_modules/next/dist/compiled/jest-worker/threadChild.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.jsView on unpkg · L1Native or WebAssembly artifact printable strings contain known collector or webhook infrastructure.
app/node_modules/@ngrok/ngrok-linux-x64-gnu/ngrok.linux-x64-gnu.nodeView on unpkgPackage ships native binary artifacts.
app/node_modules/@ngrok/ngrok-linux-x64-gnu/ngrok.linux-x64-gnu.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1View on unpkgPackage ships high-entropy non-source blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships compressed or archive-like blobs.
app/public/downloads/polyrouter-connector.zipView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
app/public/downloads/polyrouter-connector.zipView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
app/node_modules/next/dist/build/next-config-ts/transpile-config.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
app/node_modules/@next/env/dist/index.jsView on unpkgPackage source references child process execution.
app/src/mitm/server.jsView on unpkg · L32Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.jsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution with blocking evidence.
cli.jsView on unpkg · L773A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli.jsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L2Package source references dynamic code evaluation.
app/node_modules/next/dist/compiled/browserslist/index.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/cli/tray/autostart.jsView on unpkg · L3