@majkapp/majk-chat-cli
CLI for multi-provider LLM chat interactions
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/majk-chat-standalone.cjs | AI (source-diff): Bundled third-party lexer code (PDF.js-style), not obfuscation; no behavior change vs approved version. | ai | |
| phantom-deps | phantom-dep:enquirer | AI (phantom-deps): Declared and referenced in config; stable FP for this CLI. | ai | |
| source-diff | obfuscated-file:dist/majk-chat-standalone.cjs | AI (source-diff): esbuild-bundled standalone CLI output, matches documented build:standalone script. | ai | |
| source-diff | net-exec-file:dist/majk-chat-standalone.cjs | AI (source-diff): Bundled CLI containing network+exec APIs for legitimate LLM chat functionality, not a dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size jump is the new standalone bundle, explained by build script addition. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 1.0.84 | 22 / 10 | |
| 1.0.81 | 22 / 10 | |
| 1.0.56 | 16 / 10 | |
| 1.0.53 | 16 / 10 | |
| 1.0.49 | 16 / 10 | |
| 1.0.44 | 16 / 10 | |
| 1.0.42 | 16 / 10 | |
| 1.0.39 | 16 / 10 | |
| 1.0.38 | 16 / 10 | |
| 1.0.33 | 16 / 10 | |
| 1.0.32 | 16 / 10 | |
| 1.0.31 | 16 / 10 | |
| 1.0.28 | 15 / 10 | |
| 1.0.27 | 15 / 10 | |
| 1.0.25 | 15 / 10 | |
| 1.0.23 | 15 / 10 | |
| 1.0.20 | 15 / 10 | |
| 1.0.14 | 14 / 10 | |
| 1.0.13 | 14 / 10 | |
| 1.0.12 | 14 / 9 | |
| 1.0.11 | 14 / 9 | |
| 1.0.10 | 14 / 9 | |
| 1.0.9 | 14 / 9 | |
| 1.0.8 | 14 / 9 | |
| 1.0.5 | 14 / 9 | |
| 1.0.4 | 14 / 9 | |
| 1.0.3 | 14 / 9 | |
| 1.0.2 | 13 / 9 | |
| 1.0.1 | 13 / 9 |
v1.0.81
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.56
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.53
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.49
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.44
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.42
2 findingsModified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.31
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.28
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.27
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.25
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.23
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: juleswhite.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.20
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.