@baseplate-dev/plugin-ai
AI agent integration plugin for Baseplate — generates AGENTS.md, CLAUDE.md, .mcp.json, and .agents/ configuration files
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/dist-DEBEd6nn.js | AI (source-diff): Vite/module-federation bundled output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/zod-DXVFhvUz.js | AI (source-diff): Bundled zod library code, false positive on pattern match. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-vgduwF6Y.js | AI (source-diff): Module-federation runtime code, no malicious network/eval behavior in sample. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-ai__remoteEntry_js-D3epqBnk.js | AI (source-diff): Standard module-federation remoteEntry loader, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-BLj3rN_U.js | AI (source-diff): Minified bundle output from vite build, matches package's own utils/schema code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-XPVCpFzV.js | AI (source-diff): Minified bundled utils/model code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-ai__remoteEntry_js-iW1sFlLW.js | AI (source-diff): Module Federation remote-entry loader; expected network+exec pattern for this architecture. | ai | |
| source-diff | net-exec-file:dist/web/assets/zod-DY2eFIv_.js | AI (source-diff): Bundled zod library, false positive on pattern match. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_ai__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-O6r3JZAl.js | AI (source-diff): Minified vendor bundle (react/rolldown), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BmG3H7-X.js | AI (source-diff): Vite module-federation shared vendor chunk, bundled not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js | AI (source-diff): Vite module-federation shared vendor chunk, bundled not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BEoACZXa.js | AI (source-diff): Standard Vite module-federation minified bundle with source map; code samples show legitimate library code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B07HCOxC.js | AI (source-diff): Standard Vite module-federation minified bundle with source map; code samples show legitimate UI library code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DQAPSZRY.js | AI (source-diff): Standard Vite module-federation bundle artifact; minified lines are normal build output for this package. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-MqpmUdhv.js | AI (source-diff): Standard Vite module-federation bundle artifact; minified lines are normal build output for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Used in bundled Vite federation output, not direct source imports. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/utils | AI (phantom-deps): Same-org dep used transitively in build output. | ai | |
| provenance | publisher-changed | AI (provenance): Moved from manual to GitHub Actions CI/CD publishing with SLSA provenance. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BU0YFAI_.js | AI (source-diff): Vite federation bundle of sibling UI components; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-D_5bUoqQ.js | AI (source-diff): Vite federation bundle of sibling package; standard minified build output. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Used in bundled Vite federation output, not direct source imports. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org package under halfdomelabs/baseplate; stub/placeholder pattern is expected for this ecosystem. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 0.6.12 | 10 / 17 | |
| 0.6.11 | 10 / 17 | |
| 0.6.10 | 10 / 17 | |
| 0.6.9 | 10 / 17 | |
| 0.6.8 | 10 / 17 | |
| 0.6.7 | 10 / 17 | |
| 0.6.6 | 10 / 17 | |
| 0.6.5 | 10 / 17 | |
| 0.0.1 | 0 / 0 |
v0.6.12
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.