@johpaz/hive-agents
Tu colmena de agentes IA. Local-first. Multi-canal. Open source. Construido desde Colombia para el mundo.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@johpaz/hive-agents-core | AI (phantom-deps): Same-org workspace sibling, used indirectly via monorepo build. | ai | |
| phantom-deps | phantom-dep:@johpaz/hive-agents-code-bridge | AI (phantom-deps): Same-org workspace sibling, used indirectly via monorepo build. | ai | |
| phantom-deps | phantom-dep:toon-format-parser | AI (phantom-deps): Used via config wiring, not a direct import. | ai | |
| phantom-deps | phantom-dep:ollama | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:discord.js | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@ag-ui/core | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@slack/bolt | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:async-mutex | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:cron-parser | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:jsonwebtoken | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@google/genai | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@clack/prompts | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:isomorphic-git | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:puppeteer-core | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:qrcode-terminal | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@anthropic-ai/sdk | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:croner | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:grammy | AI (phantom-deps): Config-driven dependency resolution in agent framework; stable pattern. | ai | |
| provenance | no-provenance | AI (provenance): Manual publish common on npm; not a risk on its own. | ai | |
| source-diff | obfuscated-file:dist/hive.js | AI (source-diff): Bun-bundled CLI binary, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/hive.js | AI (source-diff): Bundled CLI with network+exec features by design, not a dropper. | ai | |
| source-diff | encoded-string-file:dist/tool-worker.js | AI (source-diff): Compressed font/data assets from @pdf-lib, not payload hiding. | ai | |
| phantom-deps | phantom-dep:groq-sdk | AI (phantom-deps): Monorepo workspace deps referenced indirectly via config. | ai | |
| source-diff | obfuscated-file:dist/ui/dist/assets/AgentCreateForm-yUipEHs7.js | AI (source-diff): Bundled Vite/rolldown UI asset, not true obfuscation. | ai | |
| semgrep | semgrep:shady-links-exfil-services | AI (semgrep): Telegram getMe call is part of documented Telegram channel onboarding, not exfil. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env spread to spawn own gateway child process, not sent externally. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/AgentCreateForm-yUipEHs7.js | AI (source-diff): Bundled Vite/rolldown UI asset, not true obfuscation. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.0.43 | 24 / 4 | |
| 0.0.42 | 23 / 4 | |
| 0.0.35 | 2 / 2 | |
| 0.0.34 | 4 / 2 | |
| 0.0.33 | 4 / 2 | |
| 0.0.32 | 23 / 4 | |
| 0.0.31 | 23 / 4 | |
| 0.0.30 | 23 / 4 | |
| 0.0.29 | 23 / 4 | |
| 0.0.28 | 23 / 4 | |
| 0.0.27 | 23 / 4 | |
| 0.0.26 | 25 / 5 | |
| 0.0.25 | 25 / 5 | |
| 0.0.24 | 25 / 5 | |
| 0.0.23 | 25 / 5 | |
| 0.0.22 | 25 / 5 | |
| 0.0.21 | 25 / 5 | |
| 0.0.20 | 25 / 5 |
v0.0.43
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: johpaz.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 15 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.42
27 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/cli/src/commands/gateway.ts#L382 380 | detached: true, 381 | stdio: ["ignore", openSync(logFile, "a"), openSync(logFile, "a")], > 382 | env: { ...process.env, HIVE_GATEWAY_CHILD: "1" }, 383 | }); 384 | child.unref();
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/cli/src/commands/gateway.ts#L492 490 | detached: true, 491 | stdio: ["ignore", "pipe", "pipe"], > 492 | env: { ...process.env, HIVE_DEV: "true", HIVE_GATEWAY_CHILD: "1" }, 493 | }); 494 |
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/cli/src/commands/gateway.ts#L665 663 | detached: true, 664 | stdio: ["ignore", "pipe", "pipe"], > 665 | env: { ...process.env, HIVE_GATEWAY_CHILD: "1", NO_BROWSER: "1", ...(getDistDir() ? { HIVE_DIST_DIR: getDistDir()! 666 | }); 667 |
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/cli/src/commands/mcp.ts#L125 123 | 124 | const proc = spawn(server.command, server.args || [], { > 125 | env: { ...process.env, ...server.env }, 126 | stdio: ["pipe", "pipe", "pipe"], 127 | });
URL pointing to known exfiltration/tunneling service Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/cli/src/commands/onboard.ts#L251 249 | try { 250 | const res = await fetch( > 251 | `https://api.telegram.org/bot${token}/getMe`, 252 | { signal: AbortSignal.timeout(5000) } 253 | );
URL pointing to known exfiltration/tunneling service Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/core/src/channels/telegram.ts#L178 176 | if (file.file_path) { 177 | image = { > 178 | url: `https://api.telegram.org/file/bot${this.config.botToken}/${file.file_path}`, 179 | mimeType: "image/jpeg", 180 | caption: caption || undefined,
URL pointing to known exfiltration/tunneling service Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/core/src/channels/telegram.ts#L201 199 | const filePath = file.file_path; 200 | if (filePath) { > 201 | audioUrl = `https://api.telegram.org/file/bot${this.config.botToken}/${filePath}`; 202 | } 203 | } catch (error) {
URL pointing to known exfiltration/tunneling service Source: https://github.com/johpaz/hive/blob/7ee98131f8c6edfcc8630416634e86687a372f69/packages/core/src/channels/telegram.ts#L249 247 | if (file.file_path) { 248 | document_ = { > 249 | url: `https://api.telegram.org/file/bot${this.config.botToken}/${file.file_path}`, 250 | mimeType: message.document.mime_type || "application/octet-stream", 251 | fileName: docName,
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.