@botpress/adk-cli
Command-line interface for the Botpress Agent Development Kit (ADK)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/abap-BdImnpbu-r7nnmp8y.js | AI (source-diff): Minified bundler output (syntax-highlighting grammar chunks); not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/blade-B2ZbN0F_-80sknhqw.js | AI (source-diff): False positive on minified syntax-highlighting bundle; no actual dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/actionscript-3-CfeIJUat-wa0qy2v1.js | AI (source-diff): Bundled syntax-highlighter grammar chunk; not obfuscation. | ai | |
| source-diff | obfuscated-file:assets/ui-dist/assets/actionscript-3-CfeIJUat.js | AI (source-diff): Bundled syntax-highlighter grammar chunk; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/blade-B2ZbN0F_-k5ygajk3.js | AI (source-diff): False positive in bundled syntax-highlighter chunk; no actual dropper behavior. | ai | |
| source-diff | net-exec-file:assets/ui-dist/assets/blade-B2ZbN0F_.js | AI (source-diff): False positive in bundled syntax-highlighter chunk; no actual dropper behavior. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): Fires on minified bat-language grammar bundle; no DLL hijacking behavior present. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large file count explained by bundled syntax-highlighter grammar files for many languages. | ai | |
| source-diff | obfuscated-file:dist/abap-BdImnpbu-mm2pm9t0.js | AI (source-diff): Bundled syntax-highlighter grammar chunk (Vite/esbuild output); not obfuscation. | ai | |
| source-diff | obfuscated-file:assets/ui-dist/assets/abap-BdImnpbu.js | AI (source-diff): Bundled syntax-highlighter grammar chunk; not obfuscation. | ai | |
| phantom-deps | phantom-dep:@botpress/webchat-client | AI (phantom-deps): Bundled CLI; same-org dep used transitively. Stable FP. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/sdk | AI (phantom-deps): Referenced in config files; bundled CLI pattern. Stable FP. | ai | |
| phantom-deps | phantom-dep:@botpress/client | AI (phantom-deps): Bundled CLI; same-org dep used transitively. Stable FP. | ai | |
| phantom-deps | phantom-dep:@botpress/runtime | AI (phantom-deps): Bundled CLI; same-org dep used transitively. Stable FP. | ai | |
| phantom-deps | phantom-dep:@botpress/chat | AI (phantom-deps): Bundled CLI; same-org dep used transitively, not directly imported. Stable FP for this package. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:posthog-node | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Bundled CLI; deps are consumed at build time, not imported directly in source. | ai | |
| phantom-deps | phantom-dep:@botpress/cli | AI (phantom-deps): Same-org sibling dep; bundled into dist output. | ai | |
| phantom-deps | phantom-dep:@botpress/sdk | AI (phantom-deps): Same-org sibling dep; bundled into dist output. | ai | |
| phantom-deps | phantom-dep:@botpress/adk | AI (phantom-deps): Same-org sibling dep; bundled into dist output. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:open | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Bundled CLI (ink uses react); consumed at build time. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:adm-zip | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Bundled CLI; known implicit build-time dep. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:clipboardy | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:json-schema | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Bundled CLI; deps consumed at build time. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 2.0.2 | 24 / 0 | |
| 2.0.1 | 24 / 0 | |
| 1.18.3 | 25 / 0 | |
| 1.18.2 | 25 / 0 | |
| 1.18.1 | 25 / 0 | |
| 1.18.0 | 25 / 0 |
v2.0.2
54 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
DLL side-loading command detected — potential DLL hijacking Source: https://github.com/botpress/adk/blob/7921264dafd0e1032e1a876c85dc9fd895f8e311/assets/ui-dist/assets/bat-BkioyH1T.js#L1 > 1 | !function(){try{var e="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof globalThis 2 | //# sourceMappingURL=bat-BkioyH1T.js.map 3 |
DLL side-loading command detected — potential DLL hijacking Source: https://github.com/botpress/adk/blob/7921264dafd0e1032e1a876c85dc9fd895f8e311/assets/ui-dist/assets/bat-BkioyH1T.js#L1 > 1 | !function(){try{var e="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof globalThis 2 | //# sourceMappingURL=bat-BkioyH1T.js.map 3 |
DLL side-loading command detected — potential DLL hijacking Source: https://github.com/botpress/adk/blob/7921264dafd0e1032e1a876c85dc9fd895f8e311/assets/ui-dist/assets/bat-BkioyH1T.js#L1 > 1 | !function(){try{var e="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof globalThis 2 | //# sourceMappingURL=bat-BkioyH1T.js.map 3 |
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.