Sell your spare AI capacity — the SpareAI provider CLI turns idle Claude / Codex / Gemini subscription quota into per-request income.
LPM flags this version as an AI-agent control-surface risk. On npm installation, the package fetches a remotely controlled skill and installs it into three AI-agent control surfaces. It also performs unattended OS-level third-party package installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/ui/companion.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/ui/companion.jsView on unpkg · L9A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/relay/upstream/claude-bootstrap.jsView on unpkg · L284Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/claude-bootstrap.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
scripts/probe-claude-api.mjsView on unpkg · L11Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/relay/upstream/claude-api.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skill.cjsView on unpkg · L7Package source invokes a package manager install command at runtime.
dist/utils/awal.jsView on unpkg · L14Package ships non-JavaScript build or shell helper files.
scripts/install-market-launchd.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/task/skills/youtube/_ytdlp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
companion/main.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/codex-bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/gemini-bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/task/preflight.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L20Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/relay/upstream/claude-api.jsView on unpkgPackage source invokes a package manager install command at runtime.
dist/utils/awal.jsView on unpkg · L14Package ships non-JavaScript build or shell helper files.
scripts/install-market-launchd.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/task/skills/youtube/_ytdlp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
companion/main.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/codex-bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/gemini-bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/task/preflight.jsView on unpkgPackage source references child process execution.
dist/ui/companion.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/ui/companion.jsView on unpkg · L9A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/relay/upstream/claude-bootstrap.jsView on unpkg · L284Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/relay/upstream/claude-bootstrap.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
scripts/probe-claude-api.mjsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skill.cjsView on unpkg · L7