@easbot/agent
Core Agent for the easbot monorepo ecosystem
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/acp-STZJ75XV.mjs | AI (source-diff): tsup/esbuild minified output with readable identifiers; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/agent-FF52NW42.mjs | AI (source-diff): Bundled build output, readable CLI command structure. | ai | |
| source-diff | obfuscated-file:dist/chunks/auth-2I7U24YF.mjs | AI (source-diff): Bundled build output, standard auth CLI commands. | ai | |
| source-diff | obfuscated-file:dist/chunks/build-program-43NDEGM2.mjs | AI (source-diff): Bundled build output, CLI program builder. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-KY3H2HGJ.mjs | AI (source-diff): Core utility chunk with Shell/Fetch for CLI tool; no hostile targets. | ai | |
| source-diff | obfuscated-file:dist/chunks/copilot-I52DJYYX.mjs | AI (source-diff): Bundled AI provider integration code. | ai | |
| source-diff | obfuscated-file:dist/chunks/debug-55VJ74IW.mjs | AI (source-diff): Bundled debug CLI commands. | ai | |
| source-diff | obfuscated-file:dist/chunks/gateway-45LKZAQS.mjs | AI (source-diff): Bundled gateway CLI commands. | ai | |
| source-diff | obfuscated-file:dist/chunks/github-EJCNXJ6F.mjs | AI (source-diff): Bundled GitHub integration code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundler output restructured chunks; stable pattern for this package. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Build output restructuring reduced total size; not a stub/redirect. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled into dist; false positive. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Bundled into dist; false positive. | ai | |
| source-diff | obfuscated-file:dist/chunks/acp-5ETSP2OJ.mjs | AI (source-diff): Bundler (tsup) output with long import lines; readable ESM code, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:@easbot/skills | AI (phantom-deps): Same-org package bundled into dist; false positive. | ai | |
| phantom-deps | phantom-dep:@easbot/mcp | AI (phantom-deps): Same-org package bundled into dist; false positive. | ai | |
| source-diff | obfuscated-file:dist/chunks/agent-DIH4PXI5.mjs | AI (source-diff): Bundler output; readable ESM CLI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/agent-XASWUE5W.mjs | AI (source-diff): Bundler output; readable ESM CLI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/app-NFYUJAPW.mjs | AI (source-diff): Bundler output; readable ESM TUI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/auth-NVLQUOC3.mjs | AI (source-diff): Bundler output; readable ESM auth CLI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/build-program-PBZA7QF4.mjs | AI (source-diff): Bundler output; readable ESM config/CLI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/debug-K4AJS52M.mjs | AI (source-diff): Bundler output; readable ESM debug CLI code. | ai | |
| source-diff | obfuscated-file:dist/chunks/gateway-FISRPYY3.mjs | AI (source-diff): Bundler output; consistent with rest of dist chunks. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-NP366GVR.mjs | AI (source-diff): Large bundled chunk importing well-known packages (zod, ai, remeda, fs); no hostile dynamic execution target. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): Bundled into dist chunks; phantom-dep is a false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Bundled into dist; false positive. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.2.48 | 91 / 16 | |
| 0.2.33 | 90 / 16 | |
| 0.2.25 | 90 / 16 | |
| 0.2.16 | 87 / 17 | |
| 0.2.15 | 87 / 17 | |
| 0.1.13 | 95 / 17 | |
| 0.1.11 | 95 / 17 |
v0.2.48
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.