@draht/coding-agent
Coding agent CLI with read, bash, edit, write tools and session management
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:file-type | AI (phantom-deps): Used in config/build scripts, not a supply-chain red flag. | ai | |
| phantom-deps | phantom-dep:strip-ansi | AI (phantom-deps): Used in config/build scripts, not a supply-chain red flag. | ai | |
| dependencies | unvetted-dep:@draht/rlm | AI (dependencies): Same-org sibling package pinned to identical version; monorepo internal dep. | ai | |
| dependencies | unvetted-dep:@draht/router | AI (dependencies): Same-org sibling package pinned to identical version; monorepo internal dep. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Used in config/build scripts, not a supply-chain red flag. | ai | |
| phantom-deps | phantom-dep:extract-zip | AI (phantom-deps): Used in config/build scripts, not a supply-chain red flag. | ai | |
| phantom-deps | phantom-dep:@draht/tools | AI (phantom-deps): Own-org workspace dep resolved indirectly; stable FP. | ai | |
| provenance | missing-githead | AI (provenance): Large monorepo release; publisher has consistent clean track record. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): doom.wasm is a demo extension (Doom overlay), not a backdoor binary. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): execFile calls powershell for Windows toast notification in an example extension, benign. | ai | |
| semgrep | semgrep:steganography-image-eval | AI (semgrep): Flags WAD binary file read for a Doom engine example; no steganography attack pattern present. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Declared in config files only; stable false positive for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes base64 image data and writes to disk in an image-gen example; no payload hiding. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used to load a pre-built Doom JS module in an example extension; not a dynamic code injection risk. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 localhost OAuth callback URI — not exfiltration or C2. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 2026.7.13 | 27 / 10 | |
| 2026.7.12 | 27 / 10 | |
| 2026.7.11 | 25 / 10 | |
| 2026.7.7 | 25 / 10 | |
| 2026.6.11 | 26 / 9 | |
| 2026.5.12 | 21 / 8 | |
| 2026.4.26 | 20 / 8 | |
| 2026.4.25 | 20 / 8 | |
| 2026.4.23 | 20 / 8 | |
| 2026.4.5 | 21 / 8 | |
| 2026.3.25 | 21 / 8 | |
| 2026.3.14 | 21 / 8 | |
| 2026.3.6 | 19 / 8 | |
| 2026.3.5 | 19 / 8 | |
| 2026.3.4 | 19 / 8 | |
| 2026.3.3 | 17 / 8 | |
| 2026.3.2 | 17 / 8 |
v2026.7.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2026.7.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2026.7.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.7.7
4 findingsPackage contains compiled binaries that could be backdoors: • examples/extensions/doom-overlay/doom/build/doom.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
child_process imported — can execute arbitrary system commands 35 | 36 | function notifyWindows(title: string, body: string): void { > 37 | const { execFile } = require("child_process"); 38 | execFile("powershell.exe", ["-NoProfile", "-Command", windowsToastScript(title, body)]); 39 | }
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2026.6.11
4 findingsPackage contains compiled binaries that could be backdoors: • examples/extensions/doom-overlay/doom/build/doom.wasm
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
child_process imported — can execute arbitrary system commands 35 | 36 | function notifyWindows(title: string, body: string): void { > 37 | const { execFile } = require("child_process"); 38 | execFile("powershell.exe", ["-NoProfile", "-Command", windowsToastScript(title, body)]); 39 | }
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2026.3.25
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.3.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2026.3.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.3.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.3.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.3.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: execute008.
v2026.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.