@agentc7/server
Node HTTP broker for ac7 — self-hostable agent control plane (Hono + SQLite).
9
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
andrewprzy
Keywords
ac7mcpagentbrokerserverself-hostedhonosqlite
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:public/assets/index-BFZJiDOW.js | AI (source-diff): Network calls are Workbox service-worker registration and modulepreload fetches; no arbitrary code execution. | ai | |
| source-diff | obfuscated-file:public/assets/index-BFZJiDOW.js | AI (source-diff): Vite-bundled frontend entry point; minification is expected. | ai | |
| source-diff | obfuscated-file:public/assets/common-DlXhUo7M.js | AI (source-diff): Vite-bundled frontend asset (highlight.js); minification is expected. | ai | |
| source-diff | net-exec-file:public/assets/index-DHw-G7L4.js | AI (source-diff): Network calls and dynamic script loading are normal browser bundle patterns (modulepreload polyfill, fetch); not dropper behavior. | ai | |
| source-diff | obfuscated-file:public/assets/index-DHw-G7L4.js | AI (source-diff): Standard Vite-minified frontend bundle with sourcemap; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:public/assets/common-DzJqOV7s.js | AI (source-diff): Vite-minified highlight.js bundle; well-known library. | ai | |
| source-diff | obfuscated-file:public/assets/index-BT8zYk-Z.js | AI (source-diff): Vite-minified app entry; standard PWA/Workbox pattern. | ai | |
| source-diff | net-exec-file:public/assets/index-BT8zYk-Z.js | AI (source-diff): Workbox SW registration uses fetch+dynamic import; expected PWA pattern. | ai | |
| source-diff | obfuscated-file:public/assets/workbox-window.prod.es5-DAuf_HpY.js | AI (source-diff): Workbox production bundle; minification is standard and expected. | ai | |
| source-diff | obfuscated-file:public/assets/common-BUMVzbk-.js | AI (source-diff): Vite-bundled highlight.js frontend asset; minification is expected. | ai | |
| source-diff | obfuscated-file:public/assets/index-D0XyimLQ.js | AI (source-diff): Vite app bundle; minification is expected for frontend assets. | ai | |
| source-diff | net-exec-file:public/assets/index-D0XyimLQ.js | AI (source-diff): fetch() call is Vite's modulepreload polyfill, not a dropper. | ai | |
| source-diff | obfuscated-file:public/assets/marked.esm-DlZS6SDL.js | AI (source-diff): Bundled marked.js markdown parser; minification expected. | ai | |
| source-diff | obfuscated-file:public/assets/purify.es-B7xcIeU4.js | AI (source-diff): Bundled DOMPurify; minification expected. | ai | |
| source-diff | obfuscated-file:public/assets/workbox-window.prod.es5-moKUNATN.js | AI (source-diff): Bundled workbox-window PWA library; standard minified output with source map. | ai | |
| source-diff | obfuscated-file:public/assets/client-DWauEnMw.js | AI (source-diff): Vite-bundled Preact/UI frontend asset with source map; standard minified output, not obfuscation. | ai | |
| source-diff | net-exec-file:public/assets/index-DFcJ6J6V.js | AI (source-diff): Network calls are fetch() for module preloading and service worker registration — standard Vite PWA pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:public/assets/marked.esm-d6uq5Mo2.js | AI (source-diff): Bundled marked.js markdown parser; standard minified output with source map. | ai | |
| source-diff | obfuscated-file:public/assets/purify.es-BZ-8_tV6.js | AI (source-diff): Bundled DOMPurify sanitizer; standard minified output with source map. | ai | |
| source-diff | obfuscated-file:public/assets/index-DFcJ6J6V.js | AI (source-diff): Vite-bundled main app entry with source map; standard minified output. | ai | |
| source-diff | obfuscated-file:public/assets/common-BmodZq9c.js | AI (source-diff): Vite-bundled highlight.js asset with source map; standard minified output. | ai | |
| source-diff | net-exec-file:public/assets/index-8QTBEsxx.js | AI (source-diff): Network calls and dynamic script loading are standard Vite modulepreload polyfill patterns, not malware. | ai | |
| source-diff | obfuscated-file:public/assets/index-8QTBEsxx.js | AI (source-diff): Vite-bundled frontend asset; minification is expected for a server package shipping a web UI. | ai | |
| source-diff | net-exec-file:public/assets/index-DMqpBvB5.js | AI (source-diff): Network calls and dynamic DOM manipulation are normal browser-side Vite bundle behavior, not dropper/loader malware. | ai | |
| source-diff | obfuscated-file:public/assets/index-DMqpBvB5.js | AI (source-diff): Standard Vite-bundled frontend asset; minification triggers the rule but no obfuscation or malicious payload present. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped @agentc7 package; name similarity to semver is coincidental, not impersonation. | ai |