← Home

@goondocks/myco

Collective agent intelligence — Claude Code plugin

27
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sirkirby

Keywords

mycomcpai-agentsclaude-codecodexteam-syncknowledge-graph

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/server-YYGJKVBZ.js AI (source-diff): Bundled server code with normal imports/createRequire shim; no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/ui/assets/index-CMSMi4Jb.js AI (source-diff): Vite/React bundled build output, not true obfuscation. ai
source-diff net-exec-file:dist/server-6UDN35QN.js AI (source-diff): Local server bundle importing own chunks; matches stated MCP/agent functionality. ai
source-diff net-exec-file:dist/server-DLBATUNG.js AI (source-diff): Bundled MCP server entrypoint; network+exec is the package's stated function, not injected code. ai
source-diff net-exec-file:dist/server-43KSJ65Q.js AI (source-diff): tsup-bundled server entry with normal ESM/require shim, not a dropper. ai
source-diff obfuscated-file:dist/ui/assets/index-Cq-H7wgE.js AI (source-diff): Vite-bundled frontend asset, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-DA61Ial2.js AI (source-diff): Vite/esbuild bundled frontend asset, not true obfuscation. ai
source-diff net-exec-file:dist/server-4AMZNP4F.js AI (source-diff): tsup-bundled server entry importing own chunks, no hostile exec target. ai
source-diff net-exec-file:dist/server-EBKMQISL.js AI (source-diff): Bundled MCP server entrypoint matching package's stated functionality, not a dropper. ai
source-diff net-exec-file:dist/server-JM3TM7D2.js AI (source-diff): Bundled server module implementing the package's own MCP/embedding features, not a dropper. ai
source-diff net-exec-file:dist/server-NTRVB5ZM.js AI (source-diff): tsup-bundled server entry importing internal chunks, not a dropper. ai
source-diff obfuscated-file:dist/ui/assets/index-D3SY7ZHY.js AI (source-diff): Vite-bundled frontend asset, not true obfuscation; matches build:ui script. ai
source-diff net-exec-file:dist/server-NZLZRITH.js AI (source-diff): Bundled MCP server code, not a loader; network+exec is the package's stated function. ai
source-diff large-new-source-files AI (source-diff): Bundled build output (tsup) for a plugin server, not injected code. ai
source-diff net-exec-file:dist/server-TV3D35HZ.js AI (source-diff): Bundled MCP server file; network+exec calls are legitimate LLM/embedding provider usage, not a dropper. ai
source-diff obfuscated-file:dist/ui/assets/index-DZrElonz.js AI (source-diff): Vite/React bundle output, not obfuscation; matches package's UI build. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are official Anthropic/Inquirer packages matching stated plugin functionality. ai
source-diff net-exec-file:dist/ui/assets/index-DZrElonz.js AI (source-diff): Fetch call is standard modulepreload polyfill in bundled frontend code. ai
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): Stable false positive; referenced in config files. ai
source-diff obfuscated-file:dist/ui/assets/index-D4lb-caP.js AI (source-diff): Standard Vite/React bundle output; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/ui/assets/index-D4lb-caP.js AI (source-diff): Network calls are modulepreload fetch polyfill in a React bundle; no hostile destination. ai
install-scripts install-script:postinstall AI (install-scripts): select-binary.mjs selects platform-specific prebuilt binary from optional deps — documented native binding pattern. ai
semgrep semgrep:env-spread AI (semgrep): env spread in build script adds TARGET var for cross-compilation; not exfiltration. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Likely used in scripts or config; stable false positive for this package. ai
phantom-deps phantom-dep:smol-toml AI (phantom-deps): Stable false positive; referenced in config files. ai
phantom-deps phantom-dep:shell-quote AI (phantom-deps): Stable false positive; referenced in config files. ai
phantom-deps phantom-dep:@openai/agents AI (phantom-deps): Stable false positive; referenced in config files. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): Stable false positive; referenced in config files. ai
phantom-deps phantom-dep:@anthropic-ai/claude-agent-sdk AI (phantom-deps): Stable false positive; referenced in config files. ai
source-diff net-exec-file:dist/server-J3AQ3YFA.js AI (source-diff): tsup-bundled server entry; imports LLM/embedding modules consistent with declared Claude Code plugin purpose. ai
source-diff net-exec-file:dist/chunk-6C26YFOA.js AI (source-diff): tsup-bundled ESM chunk; createRequire/__commonJS are standard CJS interop patterns, not dropper behavior. ai
phantom-deps phantom-dep:gray-matter AI (phantom-deps): Bundled by tsup; stable false positive for this package. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Bundled by tsup; stable false positive for this package. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Bundled by tsup; stable false positive for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled by tsup; not directly imported at source level but used transitively. ai
source-diff net-exec-file:dist/chunk-AOMX45LH.js AI (source-diff): tsup-bundled ESM output inlining node_modules; network calls are LLM API calls, not dropper behavior. ai
source-diff net-exec-file:dist/server-PIEPVUUH.js AI (source-diff): Same tsup bundle pattern; server entry importing LLM/embedding modules, not malware. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): Bundled by tsup; stable false positive for this package. ai

Versions (showing 27 of 27)

Version Deps Published
1.2.1 12 / 9
0.21.2 13 / 7
0.19.6 11 / 7
0.9.0 10 / 6
0.6.5 8 / 6
0.6.4 8 / 6
0.6.2 8 / 6
0.6.0 8 / 6
0.5.1 8 / 6
0.5.0 8 / 6
0.4.3 8 / 6
0.4.2 8 / 6
0.3.7 8 / 6
0.3.3 8 / 6
0.3.2 8 / 6
0.3.0 8 / 6
0.2.14 8 / 6
0.2.13 8 / 6
0.2.12 8 / 6
0.2.11 8 / 6
0.2.10 8 / 6
0.2.9 8 / 6
0.2.8 8 / 6
0.2.7 8 / 6
0.2.6 8 / 6
0.2.5 8 / 6
0.1.0 8 / 6

v0.21.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

3 findings
HIGH New obfuscated file: dist/ui/assets/index-DZrElonz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-DZrElonz.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.5

3 findings
HIGH New obfuscated file: dist/ui/assets/index-Cq-H7wgE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/server-43KSJ65Q.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.4

3 findings
HIGH New obfuscated file: dist/ui/assets/index-CMSMi4Jb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/server-6UDN35QN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

3 findings
HIGH New obfuscated file: dist/ui/assets/index-D3SY7ZHY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/server-NTRVB5ZM.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

3 findings
HIGH New obfuscated file: dist/ui/assets/index-DA61Ial2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/server-4AMZNP4F.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.1

2 findings
HIGH New file with network + code execution: dist/server-TV3D35HZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

2 findings
HIGH New file with network + code execution: dist/server-TV3D35HZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.3

2 findings
HIGH New file with network + code execution: dist/server-NZLZRITH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.2

2 findings
HIGH New file with network + code execution: dist/server-NZLZRITH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.7

2 findings
HIGH New file with network + code execution: dist/server-JM3TM7D2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.3

2 findings
HIGH New file with network + code execution: dist/server-YYGJKVBZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.2

2 findings
HIGH New file with network + code execution: dist/server-EBKMQISL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

2 findings
HIGH New file with network + code execution: dist/server-DLBATUNG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.