ShadowClaw - multi-runtime AI assistant.
No confirmed attack surface was established from the inspected source excerpts. The flagged agent locations copy documentation, and agent initialization is an explicit CLI action.
Package source references dynamic code evaluation.
dist/cli/chunk-BDSNQ5RN2.js#virtual:string-array:round1View on unpkg · L1Package source references dynamic require/import behavior.
dist/cli/chunk-BDSNQ5RN2.js#virtual:string-array:round1View on unpkg · L1Package source executes code through a VM context API.
src/worker/utils/native-eval-executor.tsView on unpkg · L18Source executes local commands and sends command output to an external endpoint.
dist/electron/main.cjsView on unpkg · L87A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/electron/main.cjsView on unpkg · L87A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli/chunk-OXLHz5Jg.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/cli/commands/agent.tsView on unpkg · L92Source reaches cloud instance metadata or link-local credential endpoints.
dist/cli/chunk-By9miObI2.jsView on unpkg · L1Source exposes local file and command tools to a remote model endpoint.
dist/public/agent.worker.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/chunk-DAfYkSQ12.jsView on unpkg · L28Package contains source files above the normal full-analysis size ceiling.
dist/server.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli/chunk-B2vnlJ9A.jsView on unpkgThis report applies to shadow-claw@1.46.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/electron/main.cjsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/electron/main.cjsView on unpkg · L87Package source references weak cryptographic algorithms.
dist/electron/main.cjsView on unpkg · L1Package source references dynamic code evaluation.
dist/cli/chunk-BDSNQ5RN2.js#virtual:string-array:round1View on unpkg · L1Package source references dynamic require/import behavior.
dist/cli/chunk-BDSNQ5RN2.js#virtual:string-array:round1View on unpkg · L1Source executes local commands and sends command output to an external endpoint.
dist/electron/main.cjsView on unpkg · L87A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/electron/main.cjsView on unpkg · L87Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/cli/commands/agent.tsView on unpkg · L92Source reaches cloud instance metadata or link-local credential endpoints.
dist/cli/chunk-By9miObI2.jsView on unpkg · L1Source exposes local file and command tools to a remote model endpoint.
dist/public/agent.worker.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/chunk-DAfYkSQ12.jsView on unpkg · L28Package contains source files above the normal full-analysis size ceiling.
dist/server.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli/chunk-B2vnlJ9A.jsView on unpkgPackage source executes code through a VM context API.
src/worker/utils/native-eval-executor.tsView on unpkg · L18Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/electron/main.cjsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/electron/main.cjsView on unpkg · L87Package source references weak cryptographic algorithms.
dist/electron/main.cjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli/chunk-OXLHz5Jg.jsView on unpkg · L1