← Home

@agentuity/cli

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

huijirop0tofpiejhaynie

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): json-colorizer is a well-known pretty-print lib, benign addition. ai
source-diff net-exec-file:src/cmd/build/ast.ts AI (source-diff): Source counterpart of the same legitimate AST module. ai
source-diff net-exec-file:dist/cmd/build/ast.js AI (source-diff): Legit AST build tooling (acorn/typescript/astring), not a dropper. ai
maintainer-change maintainer-added AI (maintainer-change): Same trusted publisher account, consistent with legitimate org publishing rotation. ai
provenance publisher-changed AI (provenance): Publisher already vetted (2229 approved/0 rejected); no behavioral change accompanies the switch. ai
provenance missing-githead AI (provenance): Major version publish by known maintainer; missing gitHead is a CI environment change, not a malware indicator for this package. ai
phantom-deps phantom-dep:adm-zip AI (phantom-deps): CLI tool uses adm-zip for archive operations; likely imported transitively or via dynamic bundler config. ai
phantom-deps phantom-dep:astring AI (phantom-deps): AST codegen tool used in build pipeline; referenced in config files as expected. ai
phantom-deps phantom-dep:acorn-loose AI (phantom-deps): JS parser used in build/analysis pipeline; referenced in config files as expected. ai
phantom-deps phantom-dep:@agentuity/auth AI (phantom-deps): Same-org package; likely re-exported or used via bundler entry points. ai
phantom-deps phantom-dep:@agentuity/frontend AI (phantom-deps): Same-org package; used via vite plugin export path, not direct import. ai
phantom-deps phantom-dep:@datasert/cronjs-parser AI (phantom-deps): Cron parsing utility; referenced in config files, stable false positive for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Active org package with frequent releases; maintainer rotation is expected and publisher is a known maintainer. ai
phantom-deps phantom-dep:git-url-parse AI (phantom-deps): git-url-parse is a declared runtime dep used via config; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@vitejs/plugin-react AI (phantom-deps): Used in vite config files; phantom-dep heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): TypeScript is a build-time tool declared as a dep for tsc; not directly imported at runtime — stable false positive for this package. ai
phantom-deps phantom-dep:@types/yazl AI (phantom-deps): @types/yazl is a type declaration package; not directly imported but used by TypeScript compiler — stable false positive. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): rundll32 user32.dll,MessageBeep is a benign Windows sound notification call. ai
semgrep semgrep:env-spread AI (semgrep): CLI tool passing process.env to child processes is standard; no exfiltration path. ai
bogus-package bogus-package AI (bogus-package): Scoped org CLI with 248 versions; missing metadata fields are cosmetic, not malicious. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @agentuity/cli is a scoped package; Levenshtein match to 'joi' is a false positive. ai
semgrep semgrep:env-bulk-read AI (semgrep): Debug-only env enumeration filtered to relevant keys; not exfiltration. ai
semgrep semgrep:base64-decode AI (semgrep): SSH key fingerprint computation; standard crypto use, no payload hiding. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Localhost (127.0.0.1) health check for dev server port — not a remote raw IP. ai

Versions (showing 51 of 237)

View all versions
Version Deps Published
3.1.14 29 / 6
3.1.13 29 / 6
3.1.12 29 / 6
3.1.11 28 / 6
3.1.10 28 / 6
3.1.9 28 / 6
3.1.8 28 / 6
3.1.7 28 / 6
3.1.6 28 / 6
3.1.5 28 / 6
3.1.4 28 / 6
3.1.3 28 / 6
3.1.2 28 / 6
3.1.1 28 / 6
3.1.0 28 / 6
3.0.12 18 / 6
3.0.11 18 / 6
3.0.10 17 / 6
3.0.9 17 / 6
3.0.8 17 / 6
3.0.7 17 / 6
3.0.6 17 / 6
3.0.5 17 / 6
3.0.4 17 / 6
3.0.3 17 / 6
3.0.2 17 / 6
3.0.1 17 / 6
3.0.0 17 / 6
2.0.30 21 / 9
2.0.29 21 / 9
2.0.28 21 / 9
2.0.27 21 / 9
2.0.26 21 / 9
2.0.25 21 / 9
2.0.24 21 / 9
2.0.23 21 / 9
2.0.22 21 / 9
2.0.21 21 / 9
2.0.20 21 / 9
2.0.19 21 / 9
2.0.18 21 / 9
2.0.17 21 / 9
2.0.16 21 / 9
2.0.15 21 / 9
2.0.14 21 / 9
2.0.13 21 / 9
2.0.12 21 / 9
2.0.11 21 / 9
2.0.10 21 / 9
2.0.9 21 / 9
2.0.8 21 / 9

v3.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.10

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: huijiro → jhaynie (on 2026-07-20, known maintainer) provenance

This version was published by a different npm account (jhaynie) than the most recent previously approved version (huijiro) on 2026-07-20, but jhaynie is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.9

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jhaynie → huijiro (on 2026-07-08, known maintainer) provenance

This version was published by a different npm account (huijiro) than the most recent previously approved version (jhaynie) on 2026-07-08, but huijiro is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: huijiro → jhaynie (on 2026-07-06, known maintainer) provenance

This version was published by a different npm account (jhaynie) than the most recent previously approved version (huijiro) on 2026-07-06, but jhaynie is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jhaynie → huijiro (on 2026-07-03, known maintainer) provenance

This version was published by a different npm account (huijiro) than the most recent previously approved version (jhaynie) on 2026-07-03, but huijiro is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: huijiro → jhaynie (on 2026-07-02, known maintainer) provenance

This version was published by a different npm account (jhaynie) than the most recent previously approved version (huijiro) on 2026-07-02, but jhaynie is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: p0tofpie → huijiro (on 2026-06-29, known maintainer) provenance

This version was published by a different npm account (huijiro) than the most recent previously approved version (p0tofpie) on 2026-06-29, but huijiro is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.30

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: huijiro → p0tofpie (on 2026-06-25, known maintainer) provenance

This version was published by a different npm account (p0tofpie) than the most recent previously approved version (huijiro) on 2026-06-25, but p0tofpie is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.