Ship PRs while you sleep. Merge them with your eyes open. The Wayari software factory from a terminal.
LPM flags this version as an AI-agent control-surface risk. Installation automatically registers Wayari as a global MCP server with installed Claude Code and Codex clients. This changes broad AI-agent control surfaces without an explicit user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/wayari.mjsView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/wayari.mjsView on unpkg · L10546Package source references weak cryptographic algorithms.
dist/wayari.mjsView on unpkg · L13Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli-postinstall.mjsView on unpkg · L3This report applies to wayari@0.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L33Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/wayari.mjsView on unpkg · L10546Package source references weak cryptographic algorithms.
dist/wayari.mjsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/wayari.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli-postinstall.mjsView on unpkg · L3