← Home

@netlify/agent-runner-cli

CLI tool for running Netlify agents

33
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

netlify-botmikewenyouvalvserhalp-netlifymlgualtieri-gatsby

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): MCP SDK loaded by convention ai
phantom-deps phantom-dep:opencode-ai AI (phantom-deps): Agent CLI dep loaded by convention ai
phantom-deps phantom-dep:zod AI (phantom-deps): Used via config/runtime convention in this monorepo tool ai
maintainer-change maintainer-added AI (maintainer-change): netlify-bot publisher has long clean track record; internal Netlify maintainer churn ai
phantom-deps phantom-dep:@netlify/cache-utils AI (phantom-deps): Framework-scoped, loaded by convention. ai
source-diff obfuscated-file:dist/interactions-mcp-server.js AI (source-diff): tsup/esbuild bundle output for new MCP server dep, not hand-obfuscated code. ai
source-diff net-exec-file:dist/interactions-mcp-server.js AI (source-diff): Bundled MCP server; network+exec is its documented function, not a dropper. ai
source-diff source-size-tripled AI (source-diff): Large multi-agent CLI bundling many SDKs; consistent with stated scope. ai
semgrep semgrep:env-spread AI (semgrep): Smoke test env construction, not exfiltration to external host. ai
maintainer-change maintainer-removed AI (maintainer-change): Netlify-bot publisher with strong track record; routine maintainer list churn. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Package declares otel deps by convention alongside @netlify/otel; not a direct import but legitimately declared. ai
publish-pattern new-deps-added AI (publish-pattern): fastify is a well-established HTTP framework; addition is benign for this Netlify CLI tool. ai
phantom-deps phantom-dep:fastify AI (phantom-deps): fastify is a legitimate dep referenced in config files; consistent with other accepted phantom-deps in this package. ai
provenance no-provenance AI (provenance): Netlify internal tooling published via netlify-bot; provenance not yet enabled but publisher track record is strong. ai
bogus-package bogus-package AI (bogus-package): Internal Netlify CLI tool; sparse README/keywords expected for org-internal tooling. ai
phantom-deps phantom-dep:@anthropic-ai/claude-code AI (phantom-deps): Agent runner spawns claude-code; not directly imported by design. ai
phantom-deps phantom-dep:@netlify/database-proxy AI (phantom-deps): Framework-scoped Netlify dep; stable FP for this package. ai
phantom-deps phantom-dep:@google/gemini-cli AI (phantom-deps): Agent runner spawns gemini-cli; not directly imported by design. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): AI SDK loaded by convention in agent runner; stable FP. ai
phantom-deps phantom-dep:@netlify/ts-cli AI (phantom-deps): Framework-scoped Netlify dep; stable FP for this package. ai
phantom-deps phantom-dep:@openai/codex AI (phantom-deps): Agent runner spawns codex as subprocess; not directly imported by design. ai
phantom-deps phantom-dep:@netlify/otel AI (phantom-deps): Framework-scoped telemetry package loaded by convention; stable FP. ai
phantom-deps phantom-dep:minimist AI (phantom-deps): CLI utility dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:openai AI (phantom-deps): AI SDK loaded by convention/config in agent runner; not a direct import by design. ai
install-scripts install-script:postinstall AI (install-scripts): Netlify org package; postinstall runs a local script, consistent with build/setup tooling across all versions. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-grpc AI (phantom-deps): OTel exporter loaded by convention via @netlify/otel; stable FP. ai

Versions (showing 33 of 33)

Version Deps Published
1.143.2 17 / 21
1.143.0 17 / 21
1.142.0 14 / 21
1.140.1 14 / 21
1.140.0 14 / 21
1.138.0 14 / 21
1.137.0 14 / 21
1.133.1 13 / 21
1.130.0 13 / 20
1.128.1 12 / 20
1.126.0 12 / 20
1.121.0 12 / 20
1.120.0 11 / 20
1.118.1 11 / 18
1.118.0 11 / 18
1.117.0 11 / 18
1.115.0 11 / 18
1.114.0 11 / 18
1.113.1 11 / 18
1.112.0 11 / 18
1.111.2 11 / 18
1.109.0 11 / 18
1.108.0 11 / 18
1.105.0 11 / 18
1.104.0 11 / 18
1.103.0 10 / 18
1.101.0 10 / 18
1.98.1 10 / 18
1.97.0 10 / 18
1.96.0 10 / 18
1.95.0 10 / 18
1.93.3 10 / 18
1.64.0 7 / 18

v1.143.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.143.0

3 findings
HIGH New obfuscated file: dist/interactions-mcp-server.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/interactions-mcp-server.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.142.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.140.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.138.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.137.0

2 findings
HIGH env-spread: scripts/smoke-dist.js:45 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/netlify/agent-runner-cli/blob/111141a71df4562133258373ff45dfc312f9fe26/scripts/smoke-dist.js#L45 43 | // pipeline (and, with the flag on, startServer). HAS_REPO=0 keeps init off the 44 | // git path; no API token means it stops at the expected credentials error. > 45 | const baseEnv = { 46 | ...process.env, 47 | NETLIFY_AGENT_RUNNER_SESSION_ID: 'smoke',

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.133.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.