@posthog/agent
TypeScript agent framework wrapping Claude Agent SDK with Git-based task execution for PostHog
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Expected artifact of trusted-publisher GitHub Actions flow with SLSA attestation. | ai | |
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Bundled tsup build output, not obfuscation or exfil. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Function deletes env keys after sanitizing; defensive, not exfil. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): Minified bundler output, no malicious behavior found. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost URL in test mock, not a real network destination. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): High-cadence CI publishing is normal for this monorepo package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Same vendoring event as size increase. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by vendoring Claude CLI + native binaries for stated purpose. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Intra-org PostHog maintainer rotation. | ai | |
| phantom-deps | phantom-dep:@openai/codex | AI (phantom-deps): Referenced via config/binary invocation, consistent with new codex adapter. | ai | |
| provenance | publisher-changed | AI (provenance): Move to GitHub Actions CI publisher is a provenance improvement, not compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are PostHog org members, consistent with internal team rotation. | ai | |
| source-diff | obfuscated-file:dist/claude-cli/cli.js | AI (source-diff): Bundled official Anthropic Claude CLI, minified build output not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Config-only usage, common false positive. | ai | |
| source-diff | net-exec-file:dist/claude-cli/cli.js | AI (source-diff): Same official Claude CLI bundle; network+exec is its documented function. | ai | |
| provenance | slsa-provenance | AI (provenance): PostHog publishes via CI with SLSA attestation consistently; stable signal for this package. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): ajv is a declared runtime dependency; phantom-dep heuristic false positive. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode in handoff-checkpoint.ts is for deserializing checkpoint file content, not obfuscated payload execution. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env to pass environment to Claude CLI subprocess is expected behavior for this agent wrapper. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Ripgrep and audio-capture binaries are vendored for Claude CLI subprocess use; consistent with package purpose and SLSA-attested build. | ai | |
| phantom-deps | phantom-dep:@types/jsonwebtoken | AI (phantom-deps): @types/jsonwebtoken listed as runtime dep alongside jsonwebtoken; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:yoga-wasm-web | AI (phantom-deps): Platform-specific binary dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:tar | AI (phantom-deps): tar is a declared runtime dependency; phantom-dep heuristic false positive. | ai |
Versions (showing 51 of 73)
| Version | Deps | Published |
|---|---|---|
| 2.3.1531 | 24 / 11 | |
| 2.3.1529 | 24 / 11 | |
| 2.3.1501 | 21 / 10 | |
| 2.3.1490 | 21 / 10 | |
| 2.3.1486 | 21 / 10 | |
| 2.3.1481 | 21 / 10 | |
| 2.3.1477 | 21 / 10 | |
| 2.3.1476 | 21 / 10 | |
| 2.3.1469 | 21 / 10 | |
| 2.3.1468 | 21 / 10 | |
| 2.3.736 | 19 / 10 | |
| 2.3.735 | 19 / 10 | |
| 2.3.727 | 19 / 10 | |
| 2.3.709 | 19 / 10 | |
| 2.3.696 | 19 / 10 | |
| 2.3.678 | 19 / 10 | |
| 2.3.670 | 19 / 10 | |
| 2.3.658 | 19 / 10 | |
| 2.3.616 | 19 / 10 | |
| 2.3.556 | 19 / 10 | |
| 2.3.478 | 19 / 10 | |
| 2.3.474 | 19 / 10 | |
| 2.3.459 | 19 / 10 | |
| 2.3.425 | 19 / 10 | |
| 2.3.326 | 19 / 9 | |
| 2.3.316 | 19 / 9 | |
| 2.3.312 | 19 / 9 | |
| 2.3.308 | 19 / 9 | |
| 2.3.306 | 19 / 9 | |
| 2.3.305 | 19 / 9 | |
| 2.3.304 | 19 / 9 | |
| 2.3.302 | 19 / 9 | |
| 2.3.298 | 19 / 9 | |
| 2.3.297 | 19 / 9 | |
| 2.3.293 | 19 / 9 | |
| 2.3.286 | 19 / 9 | |
| 2.3.285 | 19 / 9 | |
| 2.3.67 | 18 / 9 | |
| 2.3.62 | 18 / 9 | |
| 2.3.53 | 18 / 9 | |
| 2.3.46 | 18 / 9 | |
| 2.3.43 | 18 / 9 | |
| 2.3.31 | 18 / 9 | |
| 2.3.24 | 18 / 9 | |
| 2.3.22 | 18 / 9 | |
| 2.3.21 | 18 / 9 | |
| 2.3.18 | 18 / 9 | |
| 2.3.15 | 18 / 9 | |
| 2.3.13 | 18 / 9 | |
| 2.3.11 | 18 / 9 | |
| 2.3.10 | 18 / 9 |
v2.3.1531
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1529
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1501
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1490
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1486
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1481
4 findingsHTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };
HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },
HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1477
4 findingsHTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };
HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },
HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1476
4 findingsHTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };
HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },
HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1469
4 findingsHTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };
HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },
HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1468
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.67
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.62
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.53
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.46
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.43
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.31
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.24
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.22
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.21
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.18
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.15
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.13
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.11
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.3.10
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.