← Home

@agentuity/cli

14
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

huijirop0tofpiejhaynie

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Major version publish by known maintainer; missing gitHead is a CI environment change, not a malware indicator for this package. ai
phantom-deps phantom-dep:@datasert/cronjs-parser AI (phantom-deps): Cron parsing utility; referenced in config files, stable false positive for this package. ai
phantom-deps phantom-dep:@agentuity/frontend AI (phantom-deps): Same-org package; used via vite plugin export path, not direct import. ai
phantom-deps phantom-dep:@agentuity/auth AI (phantom-deps): Same-org package; likely re-exported or used via bundler entry points. ai
phantom-deps phantom-dep:acorn-loose AI (phantom-deps): JS parser used in build/analysis pipeline; referenced in config files as expected. ai
phantom-deps phantom-dep:astring AI (phantom-deps): AST codegen tool used in build pipeline; referenced in config files as expected. ai
phantom-deps phantom-dep:adm-zip AI (phantom-deps): CLI tool uses adm-zip for archive operations; likely imported transitively or via dynamic bundler config. ai
maintainer-change maintainer-removed AI (maintainer-change): Active org package with frequent releases; maintainer rotation is expected and publisher is a known maintainer. ai
phantom-deps phantom-dep:git-url-parse AI (phantom-deps): git-url-parse is a declared runtime dep used via config; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@vitejs/plugin-react AI (phantom-deps): Used in vite config files; phantom-dep heuristic false positive for config-referenced deps. ai
phantom-deps phantom-dep:@types/yazl AI (phantom-deps): @types/yazl is a type declaration package; not directly imported but used by TypeScript compiler — stable false positive. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): TypeScript is a build-time tool declared as a dep for tsc; not directly imported at runtime — stable false positive for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @agentuity/cli is a scoped package; Levenshtein match to 'joi' is a false positive. ai
semgrep semgrep:env-bulk-read AI (semgrep): Debug-only env enumeration filtered to relevant keys; not exfiltration. ai
semgrep semgrep:base64-decode AI (semgrep): SSH key fingerprint computation; standard crypto use, no payload hiding. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Localhost (127.0.0.1) health check for dev server port — not a remote raw IP. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): rundll32 user32.dll,MessageBeep is a benign Windows sound notification call. ai
semgrep semgrep:env-spread AI (semgrep): CLI tool passing process.env to child processes is standard; no exfiltration path. ai
bogus-package bogus-package AI (bogus-package): Scoped org CLI with 248 versions; missing metadata fields are cosmetic, not malicious. ai

Versions (showing 14 of 117)

Version Deps Published
0.0.57 15 / 5
0.0.56 15 / 5
0.0.55 15 / 5
0.0.53 15 / 5
0.0.52 15 / 5
0.0.51 15 / 5
0.0.50 15 / 5
0.0.49 14 / 3
0.0.48 14 / 3
0.0.47 13 / 3
0.0.46 13 / 3
0.0.45 13 / 3
0.0.44 13 / 3
0.0.43 8 / 2

v0.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.50

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.