← Home

@livekit/plugins-ai-coustics

This is a node plugin for adding Ai-coustics noise cancellation to an [rtc-node](https://npmjs.com/@livekit/rtc-node) `AudioStream`.

7
Versions
SEE LICENSE IN https://livekit.io/legal/terms-of-service
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

rdsathedavidzhaofeepslkmatkam_livekitraja-livekitlivekitherzoglukasiopaulwedliulkdanm_livekitocupe_livekitcacheonlysfkatbcherrylkrektdeckardtom.ezquerrothomasyuill-livekitlk-toubatbrianrgauslivekit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publish for official @livekit scope; benign automation transition. ai
install-scripts install-script:postinstall AI (install-scripts): Downloads native lib for ffi-rs/uniffi binding; consistent with LiveKit's native plugin pattern. ai
provenance publisher-changed-stale AI (provenance): CI-based publish (GitHub Actions) for an established, long-lived package; not a takeover pattern. ai
maintainer-change maintainer-removed AI (maintainer-change): LiveKit org uses GitHub Actions CI publishing; maintainer list changes reflect org restructuring, not a takeover. ai
bogus-package bogus-package AI (bogus-package): Minimal README/metadata is consistent with LiveKit's SDK plugin pattern across their package ecosystem. ai
dependencies unvetted-dep:uniffi-bindgen-react-native AI (dependencies): Platform-specific native binding toolchain dep; phantom-dep analyzer confirms it's not directly imported at runtime. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): Build tooling dep used in config, not directly imported in source; stable pattern for this package. ai
phantom-deps phantom-dep:uniffi-bindgen-react-native AI (phantom-deps): Platform-specific binary package for native bindings; stable false positive for this package. ai
phantom-deps phantom-dep:ref-napi AI (phantom-deps): Native FFI binding dep; referenced in config, not directly imported — expected for this package type. ai
phantom-deps phantom-dep:unzipper AI (phantom-deps): Used for binary extraction in native binding setup; stable false positive for this package. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Used for binary download in native binding setup; stable false positive for this package. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): Optional logging prettifier; referenced in config, not directly imported — expected pattern. ai
phantom-deps phantom-dep:@types/unzipper AI (phantom-deps): Type definitions for unzipper; framework-scoped, stable false positive. ai

Versions (showing 7 of 7)

Version Deps Published
0.2.14 4 / 3
0.2.13 4 / 3
0.2.10 9 / 4
0.2.5 9 / 4
0.1.11 9 / 4
0.1.2 9 / 4
0.0.1 0 / 0

v0.2.5

2 findings
HIGH Publisher changed: rgauslivekit → GitHub Actions (on 2026-03-17) provenance

This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

3 findings
HIGH Package has 'postinstall' script install-scripts

Script: tsx download-lib.ts --skip-if-exists

HIGH Publisher changed: rgauslivekit → GitHub Actions (on 2026-02-12) provenance

This version was published by a different npm account than previous versions on 2026-02-12. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

3 findings
HIGH Package has 'postinstall' script install-scripts

Script: tsx download-lib.ts --skip-if-exists

MEDIUM Publisher changed: rgauslivekit → GitHub Actions (on 2026-01-07, unremoved on npm for 192d) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (rgauslivekit) on 2026-01-07. It has since remained available on npm for 192 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.