Lines 1-46javascript
2import {Command}from'commander';import pe from'fs';import le from'path';import De from'os';import {z}from'zod';import Pt from'readline/promises';import {stdout,stdin}from'process';import X from'chalk';import Bi from'ora';import ge from'fs/promises';import {exec,spawn,execSync}from'child_process';import {promisify}from'util';import Ca from'zlib';import wr from'crypto';import {createTwoFilesPatch}from'diff';import dc from'http';import kc from'readline';var rn="1.0.6",an=process.env.THENUX_API_BASE_URL||"https://thenux-kyrex-ai.scieovlogs12345.workers.dev",dt=an,ke="t-nex-1.0",os=["t-nex-cli","t- ...
3`);s=c.pop()||"";for(let l of c){let d=l.trim();if(!(!d||d==="data: [DONE]")&&d.startsWith("data: "))try{let m=JSON.parse(d.slice(6).trim()),p=m.response||m.text||m.content||"";p&&(o+=p,t(p));}catch{}}}else if(typeof a.getReader=="function"){let r=a.getReader();for(;;){let{done:i,value:c}=await r.read();if(i)break;let l=n.decode(c,{stream:!0}),d=(s+l).split(`
CriticalSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/index.jsView on unpkg · L1 HighChild Process
Package source references child process execution.
dist/index.jsView on unpkg · L1 HighRemote Agent Bridge
Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L1 4`);s=d.pop()||"";for(let m of d){let p=m.trim();if(!(!p||p==="data: [DONE]")&&p.startsWith("data: "))try{let u=JSON.parse(p.slice(6).trim()),b=u.response||u.text||u.content||"";b&&(o+=b,t(b));}catch{}}}r.releaseLock();}}catch{}return o}var ds=Ui;var ao=/sorry,?\s*thenux\s*ai\s*could\s*not\s*generate\s*a\s*reply/i;function ms(a){let t=String(a||"").trim().toLowerCase();return t==="t-nex cli"||t==="t-nex-cli"?"t-nex-cli":t==="t-nex"||t==="t-nex 1.0"?"t-nex-1.0":t==="t-nex 2.0"?"t-nex-2.0":t==="t-nex prime"?"t-nex-prime":t==="t-nex ultra"?"t-nex-ultra":a}var N=class a{apiKey;baseUrl;timeout;const ...
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1 5Active Model: ${t.model} \u26A1
6Identity: You are strictly Thenux AI. You are NOT Gemini, Claude, or OpenAI. Never claim to be Gemini or any other model.
8- Maintain conversation memory and remember details the user shares with you.
9- Always provide clear, direct, and production-ready responses.`;r=r?`${d}
11${r}`:d;}r&&(s.system_prompt=r),t.messages&&t.messages.length>0&&(s.messages=t.messages.filter(d=>d.role!=="system").map(d=>({role:d.role==="assistant"?"assistant"
12Active Model: ${o} \u26A1
13Identity: You are strictly Thenux AI. You are NOT Gemini, Claude, or OpenAI. Never claim to be Gemini or any other model.
15- Maintain conversation memory and remember details the user shares with you.
16- Always provide clear, direct, and production-ready responses.`;c=c?`${m}
18${c}`:m;}c&&(i.system_prompt=c),t.messages&&t.messages.length>0&&(i.messages=t.messages.filter(m=>m.role!=="system").map(m=>({role:m.role==="assistant"?"assistant":"user",content:m.content})));let l;try{l=await fetch(r,{method:"POST",headers:this.getAuthHeaders(),body:JSON.stringify(i)});}catch{let p=await this.chat(t);return n(p),p}if(!l.ok||!l.body){let m=await this.chat(t);return n(m),m}let d=await ds(l.body,n);if(ao.test(d)){let m=await this.chat(t);return n(m),m}return d}async getCloudChatMemory(t){try{let n=`${this.baseUrl}/api/chats/${encodeURIComponent(t)}/memory?api_key=${encodeURICom ...
19`);}else console.log(` ${e.success("\u25CF")} ${e.light("Connected to THENUX AI Autonomous Edge Network")}
20`);console.log(` ${e.muted("Model Core")} ${e.bold(e.white(o))} ${e.dim("\xB7")} ${e.success("READY")}`),console.log(` ${e.muted("Workspace")} ${e.light(n)}`),console.log(` ${e.muted("Active UI")} ${e.brand(s.toUpperCase())} ${e.dim("\xB7")} ${e.dim("Type /theme to change")}`),console.log(""),console.log(` ${e.dim("Quick Shortcuts:")} ${e.brand("/help")} ${e.dim("\xB7"
21 ${e.dim(r)}${e.dim(o)}${e.dim("\u2500\u2500")}
22`);}function xs(){console.log(` ${e.dim("/help")} ${e.dim("/workspace")} ${e.dim("/theme")} ${e.dim("/browse")} ${e.dim("/play"
23`);}var E=class{spinner=null;set text(t){this.spinner&&(this.spinner.text=e.muted(t));}start(t){let n=t||"";return this.spinner?(n&&(this.spinner.text=e.muted(n)),this):(this.spinner=Bi({text:e.muted(n),prefixText:" ",spinner:{interval:80,frames:["\u25CC","\u25D0","\u25D3","\u25D1
24`)}async execute(t,n,o){let s=this.tools.get(t);if(!s)return {success:false,error:`Tool "${t}" is not registered in the toolset.`};let r=s.schema||s.parameters,i=r?r.safeParse(n):{success:true,data:n};if(!i.success){let c=i.error.errors.map(l=>`${l.path.join(".")}: ${l.message}`).join(", ");return {success:false,error:`Invalid parameters for
25`).map(r=>r.trim()).filter(r=>r&&!r.startsWith("#"));for(let r of s)this.patterns.
26`);return {filePath:a,totalLines:c,startLine:l,endLine:d,content:p,rawContent:m.join(`
27`)}}catch(r){throw new Error(`Cannot read file "${a}": ${r.message}`)}}},Es={name:"write_file",description:"Write complete content to a file. Overwrites existing files or creates new files if they do not exist.",riskLevel:"CAUTION",schema:z.object({filePath:z.string().describe("Relative path to the file"),content:z.
28Reason: ${r.reason}`,r.level))return {command:a,status:"rejected",message:"Command execution cancelled by user."};if(s.dryRun)return {command:a,riskLevel:r.level,status:"simulated (dry-run)"};let i=s.workspaceRoot;if(t){let l=le.resolve(s.workspaceRoot,t);pe.existsSync(l)&&pe.statSync(l).isDirectory()&&(i=l);}let c=Date.now();try{let{stdout:l,stderr:d}=await Vi(a,{cwd:i,timeout:n,maxBuffer:10485760,env:{...process.env,CI:"true",THENUX_AGENT:"true"}}),m=((Date.now()-c)/1e3).toFixed(1);return {command:a,cwd:i,exitCode:0,stdout:l.trim(),stderr:d.trim(),durationMs:Date.now()-c,formattedSummary:`Ex ...
29`):[];return {branch:o,clean:s.length===0,changedFilesCount:s.length,status:n||"Working tree clean"}}catch(n){return {available:false,error:n.message}}}},gn={name:"git_diff",description:"View current uncommitted changes (git diff) in the workspace.",riskLevel:"SAFE",schema:z.object({staged:z.boolean().default(false).describe("Whether to view staged changes (--cached)")}),execute:async({staged:a},t)=>{try{let o=await go(a?"diff --cached":"diff",t.workspaceRoot);return {hasDiff:o.length>0,diff:o||"No changes detected."}}catch(n){return {available:false,error:n.message}}}};var J=class{memoryFile; ...
30${t.customInstructions}`),t.conventions.length>0&&n.push(`Project Conventions:
31- ${t.conventions.join(`
32- `)}`),t.decisions.length>0&&n.push(`Architectural Decisions:
34- `)}`),t.importantMemories.length>0){let o=t.importantMemories.map(s=>`- [${s.type.toUpperCase()}]: ${s.content.replace(/\n+/g,
35`);n.push(`Important Memories from Earlier Conversation:
36${o}`);}return t.notes.length>0&&n.push(`Project Notes:
38- `)}`),n.length>0?n.join(`
40`):""}};var Hs={name:"manage_memory",description:"Store or recall architectural decisions, project conventions, user preferences, or important notes in THENUX memory.",riskLevel:"SAFE",schema:z.object({action:z.enum(["save","recall","clear"]).describe("Action to perform: save, recall, or clear"),content:z.string().optional().describe(
41#### Headings:
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L1 HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/index.jsView on unpkg · L1 42${n.headings.map(s=>`- ${s}`).join(`
44#### Page Content Preview:
45${n.contentExcerpt}`,n.links.length>0&&!a.describeOnly?`
46#### Available Outgoing Links (${n.links.length}):
Long lines were clipped for display.