Privateer — a provider-agnostic, safe-by-default terminal coding agent with TEE/Tinfoil attestation, rebuilt on the Pi toolkit. Bring your own model across 20 providers.
LPM treats this as warn-only first-party agent extension lifecycle risk. This is a powerful coding-agent CLI that installs its own extension shims on user launch and can optionally create a resident per-user daemon. No unconsented install-time mutation or concrete exfiltration chain was found.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/privateer-launch.mjsView on unpkgPackage source references child process execution.
bin/privateer-launch.mjsView on unpkg · L14Package source references dynamic require/import behavior.
bin/privateer-daemon.mjsView on unpkg · L28Source writes installer persistence such as shell profile or service configuration.
src/daemon/service.tsView on unpkg · L9Package source invokes a package manager install command at runtime.
extensions/privateer-brand.tsView on unpkg · L322Package ships non-JavaScript build or shell helper files.
bin/privateer.cmdView on unpkgPackage source references child process execution.
bin/privateer-launch.mjsView on unpkg · L14This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/privateer-launch.mjsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/privateer.cmdView on unpkgPackage source references dynamic require/import behavior.
bin/privateer-daemon.mjsView on unpkg · L28Source writes installer persistence such as shell profile or service configuration.
src/daemon/service.tsView on unpkg · L9Package source invokes a package manager install command at runtime.
extensions/privateer-brand.tsView on unpkg · L322