Multi-channel AI gateway with extensible messaging integrations
npm installation automatically modifies a hoisted third-party AI dependency and removes legacy OpenClaw state directories. These actions occur without a user command after install.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/proxy-cli.runtime-BWHciWzX.jsView on unpkg · L764Package source references dynamic require/import behavior.
dist/status.gather-C91Qzjwd.jsView on unpkg · L41Package source references weak cryptographic algorithms.
dist/short-term-promotion-CskyJ4xw.jsView on unpkg · L2Source writes installer persistence such as shell profile or service configuration.
dist/restart-C_iPYGsU.jsView on unpkg · L12Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-CKP5GwLX.jsView on unpkg · L6897Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/llm-wiki-ingest/tests/test_ingest_scripts.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/llm-wiki-ingest/tests/test_ingest_scripts.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/approval-native-runtime-B7-Q8YuY.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/plugin-test-contracts.jsView on unpkgThis report applies to sealclaw@2026.9.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L1429Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L1430Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-CKP5GwLX.jsView on unpkg · L6897Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
skills/llm-wiki-ingest/tests/test_ingest_scripts.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
skills/llm-wiki-ingest/tests/test_ingest_scripts.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/approval-native-runtime-B7-Q8YuY.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin-sdk/plugin-test-contracts.jsView on unpkgPackage contains a possible secret pattern.
dist/proxy-cli.runtime-BWHciWzX.jsView on unpkg · L764Package source references dynamic require/import behavior.
dist/status.gather-C91Qzjwd.jsView on unpkg · L41Package source references weak cryptographic algorithms.
dist/short-term-promotion-CskyJ4xw.jsView on unpkg · L2Source writes installer persistence such as shell profile or service configuration.
dist/restart-C_iPYGsU.jsView on unpkg · L12