Agent Client Protocol (ACP) server bridging headless ZCode to editors like Zed and JetBrains.
No malicious attack was identified. The launchd relaunch behavior is part of the remote hub's sandbox handling and runs when the hub is started in that condition.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/remote/hub-sandbox.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/remote/hub-sandbox.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/remote/hub-sandbox.jsView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/resolve.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/remote/hub-server.jsView on unpkgThis report applies to zcode-acp-server@0.48.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L49Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L49A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/backend/resolve.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/remote/hub-server.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/remote/hub-sandbox.jsView on unpkg · L14Source writes installer persistence such as shell profile or service configuration.
dist/remote/hub-sandbox.jsView on unpkg · L14Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/remote/hub-sandbox.jsView on unpkg