@oh-my-pi/pi-coding-agent
Coding agent CLI with read, bash, edit, write tools and session management
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Used via config/build tooling, not a direct import; benign. | ai | |
| phantom-deps | phantom-dep:ndjson | AI (phantom-deps): Used via config/build tooling, not a direct import; benign. | ai | |
| source-diff | net-exec-file:src/vendor/photon/index.js | AI (source-diff): Generated wasm-bindgen glue code, not a dropper/loader. | ai | |
| source-diff | obfuscated-file:src/vendor/photon/photon_rs_bg.wasm.b64.js | AI (source-diff): wasm-bindgen base64-embedded binary for photon image lib, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/cli.js | AI (source-diff): Bundled agent CLI; strings are prompt/tool-call templates, no observed exfil behavior. | ai | |
| dependencies | unvetted-dep:@oh-my-pi/pi-catalog | AI (dependencies): First-party monorepo sibling package pinned to same version. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-autocomplete | AI (phantom-deps): oclif plugin declared in config; stable pattern for this CLI framework. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Feature expansion (browser automation, docs) explains large new file count, no malicious content found. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps match browser-automation/HTML-parsing feature set of the agent. | ai | |
| dependencies | unvetted-dep:@oh-my-pi/pi-mnemopi | AI (dependencies): Own scoped sibling package pinned to same version. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Established templating lib; benign for this agent. | ai | |
| provenance | publisher-changed | AI (provenance): Manual→GitHub Actions CI/CD with SLSA attestation; legitimate maintainer/CI transition. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Used via config/instrumentation wiring, common for OTel setup. | ai | |
| source-diff | net-exec-file:dist/cli.js | AI (source-diff): Bundled CLI with legitimate network/module-loading code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/cli.js | AI (source-diff): Bun bundler output for the package's own CLI binary, not obfuscation. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): photon_rs_bg.wasm is the well-known photon image-processing WASM binary. | ai | |
| phantom-deps | phantom-dep:@openai/agents | AI (phantom-deps): Same phantom-dep heuristic false positive pattern. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Same phantom-dep heuristic false positive pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() used for browser page.evaluate() in a browser automation tool is expected and documented. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Guard checks for dev-only file; no-op in published package. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): The match is inside a blocklist/denylist regex array in bash.ts — defensive code, not credential harvesting. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy get-trap pattern; not obfuscation. | ai | |
| phantom-deps | phantom-dep:@types/turndown | AI (phantom-deps): Type-only dev dependency loaded by framework convention. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Phantom dep heuristic false positive; zod referenced in config files is common for type validation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding image data into a blob store is a normal image-handling pattern. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): env enumeration is filtered by SECRET_ENV_PATTERNS for a secrets-scanning feature; expected behavior. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw IPs are localhost/127.0.0.1 defaults for local Ollama service; not exfiltration. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): rundll32 url.dll,FileProtocolHandler is the standard Windows shell URL-open idiom; not a hijack vector. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into a git subprocess environment is standard practice for CLI tools. | ai | |
| phantom-deps | phantom-dep:handlebars | AI (phantom-deps): Phantom dep heuristic false positive; handlebars referenced in config without direct import is plausible. | ai |
Versions (showing 55 of 155)
| Version | Deps | Published |
|---|---|---|
| 12.14.1 | 22 / 3 | |
| 12.14.0 | 22 / 3 | |
| 12.13.0 | 22 / 3 | |
| 12.12.3 | 22 / 3 | |
| 12.12.2 | 22 / 3 | |
| 12.12.1 | 22 / 3 | |
| 12.12.0 | 22 / 3 | |
| 12.11.2 | 22 / 3 | |
| 12.11.1 | 22 / 3 | |
| 12.11.0 | 22 / 3 | |
| 12.10.1 | 22 / 3 | |
| 12.10.0 | 22 / 3 | |
| 12.7.6 | 22 / 3 | |
| 12.7.5 | 22 / 3 | |
| 12.7.4 | 22 / 3 | |
| 12.7.3 | 22 / 3 | |
| 12.7.2 | 22 / 3 | |
| 12.7.1 | 22 / 3 | |
| 12.7.0 | 22 / 3 | |
| 12.6.0 | 22 / 3 | |
| 12.5.1 | 22 / 3 | |
| 12.5.0 | 22 / 3 | |
| 12.4.0 | 22 / 3 | |
| 12.3.0 | 22 / 3 | |
| 12.2.1 | 22 / 3 | |
| 12.2.0 | 22 / 3 | |
| 12.1.1 | 22 / 3 | |
| 12.1.0 | 22 / 3 | |
| 12.0.0 | 22 / 3 | |
| 11.14.5 | 22 / 3 | |
| 11.14.4 | 22 / 3 | |
| 11.14.3 | 22 / 4 | |
| 11.14.2 | 22 / 4 | |
| 11.14.1 | 22 / 4 | |
| 11.14.0 | 22 / 4 | |
| 11.10.3 | 21 / 4 | |
| 11.5.0 | 23 / 5 | |
| 11.0.3 | 22 / 6 | |
| 10.2.3 | 20 / 4 | |
| 10.2.0 | 20 / 4 | |
| 9.8.0 | 20 / 4 | |
| 9.6.1 | 20 / 4 | |
| 9.3.1 | 19 / 4 | |
| 9.2.5 | 19 / 4 | |
| 8.8.8 | 21 / 4 | |
| 6.8.0 | 23 / 5 | |
| 4.9.0 | 25 / 5 | |
| 2.2.1337 | 17 / 3 | |
| 2.1.1337 | 17 / 3 | |
| 2.0.1337 | 17 / 3 | |
| 1.341.0 | 15 / 3 | |
| 1.340.0 | 15 / 3 | |
| 1.338.0 | 15 / 3 | |
| 1.337.1 | 15 / 3 | |
| 1.337.0 | 15 / 3 |
v12.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.12.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.12.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.10.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v11.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.8
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: can1357.
v6.8.0
5 findings[Reject — re-review on republish] (prior reject: AI (npm-metadata): Native binary with randomized filename suffix bundled alongside obfuscated code is a strong backdoor indicator.) Package contains compiled binaries that could be backdoors: • src/vendor/photon/photon_rs_bg.wasm
[Reject — re-review on republish] (prior reject: AI (provenance): Provenance regression is a hard reject signal for this package; generalizes until attestation is restored.) This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: can1357.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.