One CLI for all your AI coding agents - versions, config, cloud dispatch, sessions, and teams (now with first-class Grok Build CLI support)
Drift inferred · capture-to-capture
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
- HIGH code analysis flagged committed secret in phnx-labs/agents-cli
transport stdio · http counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v1.22.50 · analyzer v33 · 2w ago
skills & prompt files 17
- agent-rules phnx-labs-agi-cli-9006de7/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/cli/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/cli/src/lib/daemon/AGENTS.md
- skill phnx-labs-agi-cli-9006de7/cli/tests/fixtures/project-resources/repo/.agents/skills/myskill/SKILL.md
- agent-rules phnx-labs-agi-cli-9006de7/native/computer-mac/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/native/computer-win/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/packages/agi-cli/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/packages/session-tracker/AGENTS.md
- agent-rules phnx-labs-agi-cli-9006de7/packages/swarmify-mirror/AGENTS.md
- skill phnx-labs-agi-cli-9006de7/skills/browser/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/devices/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/routines/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/run/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/secrets/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/sessions/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/teams/SKILL.md
- skill phnx-labs-agi-cli-9006de7/skills/workflows/SKILL.md
danger signals17
- dynamic code execution new Function() phnx-labs-agi-cli-9006de7/cli/src/lib/traces/worker-template.test.ts :56
const fn = new Function( - suspicious endpoint mcp.posthog.com (telemetry) phnx-labs-agi-cli-9006de7/cli/src/commands/inspect.test.ts :474
expect(summarizeMcp({ name: 'posthog', transport: 'http', url: 'https://mcp.posthog.com' })) - over-broad OAuth scope https://mail.google.com/ phnx-labs-agi-cli-9006de7/cli/src/lib/browser/domain-skills.test.ts :77
const r = resolveDomainSkill('https://mail.google.com/mail/u/0/'); - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/commands/accounts.test.ts :247
sk-ant…(35 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/__tests__/runner.test.ts :463
sk-ant…(34 chars, redacted) - committed secret Google OAuth client secret phnx-labs-agi-cli-9006de7/cli/src/lib/accounting/usage.ts :3347
GOCSPX…(35 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/claude-account-token.test.ts :78
sk-ant…(36 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/crabbox/runtimes.test.ts :269
sk-ant…(31 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/exec.test.ts :1174
sk-ant…(45 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/harness/adapters/claude.test.ts :56
sk-ant…(32 chars, redacted) - committed secret OpenAI key phnx-labs-agi-cli-9006de7/cli/src/lib/session/trajectory-html.compare.test.ts :45
sk-sup…(29 chars, redacted) - committed secret OpenAI key phnx-labs-agi-cli-9006de7/cli/src/lib/session/trajectory-html.test.ts :43
sk-sup…(29 chars, redacted) - committed secret OpenAI key phnx-labs-agi-cli-9006de7/cli/src/lib/session/trajectory-text.compare.test.ts :56
sk-sup…(29 chars, redacted) - committed secret OpenAI key phnx-labs-agi-cli-9006de7/cli/src/lib/session/trajectory-text.test.ts :110
sk-sup…(29 chars, redacted) - committed secret OpenAI key phnx-labs-agi-cli-9006de7/cli/src/lib/session/trajectory.test.ts :207
sk-sup…(29 chars, redacted) - committed secret Anthropic key phnx-labs-agi-cli-9006de7/cli/src/lib/share/publish.test.ts :978
sk-ant…(33 chars, redacted) - credential in logs credential in log phnx-labs-agi-cli-9006de7/cli/src/commands/secrets.ts :2664
console.log(password);
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 1955
filesystem 400
- fs phnx-labs-agi-cli-9006de7/.agents/artifacts/2026-08-07/analyze-verify-work-complete.ts :4
import { existsSync, readFileSync, readdirSync, writeFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/.github/workflows/ci.test.ts :10
import { readFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/.github/workflows/computer-helper-win.test.ts :20
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/.github/workflows/tests-gate.test.ts :8
import { readFileSync } from 'node:fs'; - fs phnx-labs-agi-cli-9006de7/cli/bench/sessions-active-perf.ts :75
import * as fs from 'fs'; - fs phnx-labs-agi-cli-9006de7/cli/bench/sessions-perf.ts :24
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/backfill-changelog.ts :10
import { mkdirSync, readFileSync, writeFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/bench-staleness.ts :11
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/bound-repo-root.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/create-annotated-release-tag.test.ts :12
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/gen-changelog.test.ts :1
import { readFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/gen-changelog.ts :21
import { readFileSync, readdirSync, statSync, writeFileSync } from 'node:fs';
show 28 more
- fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/gen-command-index.ts :23
import { writeFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/install-helper.js :18
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/install.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/menubar-build.test.ts :2
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/postinstall.js :6
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/postinstall.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/promote-home-base-probe.test.ts :14
import * as fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/publish-computer-helper-mac.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/publish-computer-win.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-attestation-produce.test.ts :11
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-attestation.test.ts :8
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-changelog.ts :10
import { existsSync, readFileSync, readdirSync, rmSync, writeFileSync } from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-install-smoke.test.ts :7
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-lease.test.ts :17
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-manifest.test.ts :7
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-worktree.test.ts :2
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release.test.ts :2
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sample-session-shell-commands.test.ts :2
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sample-session-shell-commands.ts :4
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sandbox.test.ts :2
import fs from 'node:fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/select-publish-commit.test.ts :16
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/signing-home-base-probe.test.ts :21
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/stuck-release.test.ts :13
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/test.test.ts :3
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/verify-cli-binary.test.ts :4
import * as fs from 'fs'; - fs (weak) phnx-labs-agi-cli-9006de7/cli/scripts/verify-menubar-helper.test.ts :23
import * as fs from 'node:fs'; - fs phnx-labs-agi-cli-9006de7/cli/src/bootstrap.ts :18
import * as fs from 'fs'; - fs phnx-labs-agi-cli-9006de7/cli/src/cli/command-registry.ts :22
import { readFileSync } from 'node:fs';
360 more not shown — this panel samples each group; the count above is the real total.
shell / exec 361
- shell phnx-labs-agi-cli-9006de7/.agents/artifacts/2026-08-07/analyze-verify-work-complete.ts :7
import { spawnSync } from 'node:child_process'; - shell phnx-labs-agi-cli-9006de7/.agents/artifacts/2026-08-25/mine-teams-sessions.ts :53
const proc = Bun.spawnSync(argv, { stdout: "pipe", stderr: "pipe", timeout }); - shell (weak) phnx-labs-agi-cli-9006de7/.github/workflows/artifact-layout.test.ts :21
import { execFileSync } from 'node:child_process'; - shell phnx-labs-agi-cli-9006de7/cli/bench/sessions-active-perf.ts :57
* `process.env.PATH` at runtime does not reach a later `spawnSync('ssh', ...)` - shell phnx-labs-agi-cli-9006de7/cli/bench/sessions-perf.ts :23
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/bench-ssh.mjs :23
import { execSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/bound-repo-root.test.ts :2
import { execFileSync, execSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/create-annotated-release-tag.test.ts :11
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/install-helper.js :17
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/install.test.ts :2
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/postinstall.js :10
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/postinstall.test.ts :2
import { spawnSync } from 'child_process';
show 28 more
- shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/promote-home-base-probe.test.ts :13
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/publish-computer-helper-mac.test.ts :2
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/publish-computer-win.test.ts :2
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-attestation-produce.test.ts :9
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-attestation.test.ts :7
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-install-smoke.test.ts :6
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-lease.test.ts :16
import { spawn, spawnSync, type ChildProcess } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-manifest.test.ts :6
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release-worktree.test.ts :1
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/release.test.ts :1
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sample-session-shell-commands.test.ts :201
"import { spawnSync } from 'child_process';", - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sample-session-shell-commands.ts :3
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/sandbox.test.ts :1
import { spawnSync } from 'node:child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/select-publish-commit.test.ts :15
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/signing-home-base-probe.test.ts :20
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/stuck-release.test.ts :12
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/test.test.ts :2
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/validate-bump.test.ts :12
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/verify-cli-binary.test.ts :2
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/scripts/verify-menubar-helper.test.ts :22
import { spawnSync } from 'node:child_process'; - shell phnx-labs-agi-cli-9006de7/cli/src/bootstrap.ts :565
const { spawnSync } = await import('child_process'); - shell (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/__tests__/beta.test.ts :4
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/__tests__/inspect.test.ts :6
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/__tests__/sessions-bookmark.cli.test.ts :6
import { spawnSync } from 'child_process'; - shell (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/__tests__/sessions-stats.cli.test.ts :6
import { spawnSync } from 'child_process'; - shell phnx-labs-agi-cli-9006de7/cli/src/commands/accounts.ts :591
const { spawnSync } = await import('child_process'); - shell (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/alias.test.ts :10
import { spawnSync } from 'child_process'; - shell phnx-labs-agi-cli-9006de7/cli/src/commands/browser.ts :3
import { spawnSync } from 'node:child_process';
321 more not shown — this panel samples each group; the count above is the real total.
network 66
- net phnx-labs-agi-cli-9006de7/cli/src/bootstrap.ts :345
const response = await fetch(`https://unpkg.com/@phnx-labs/agents-cli@${toVersion}/CHANGELOG.md`); - net (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/auth.test.ts :5
import * as http from 'http'; - net phnx-labs-agi-cli-9006de7/cli/src/commands/factory.ts :50
const res = await fetch(`${factoryUrl}/factory/submit`, { - net phnx-labs-agi-cli-9006de7/cli/src/commands/share.ts :145
const res = await fetch(url, { headers: { accept: 'application/json' } }); - net phnx-labs-agi-cli-9006de7/cli/src/commands/webhook.ts :9
import type { Server } from 'http'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/accounting/usage.test.ts :880
// Driven through a real provider fetch (Kimi) with a credential file that - net phnx-labs-agi-cli-9006de7/cli/src/lib/accounting/usage.ts :466
return source ? source.fetch(options) : { snapshot: null, error: null }; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/auth-health.test.ts :326
describe('probeAuthHealth derives live from a fresh usage fetch (RUSH-3036)', () => { - net phnx-labs-agi-cli-9006de7/cli/src/lib/auto-pull-worker.ts :92
await git.fetch('origin'); - net phnx-labs-agi-cli-9006de7/cli/src/lib/browser/cdp.ts :247
response = await fetch(`http://${host}:${port}/json/version`, { signal: controller.signal }); - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/chrome.test.ts :4
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/drivers/local.test.ts :2
import * as net from 'net';
show 28 more
- net phnx-labs-agi-cli-9006de7/cli/src/lib/browser/drivers/local.ts :1
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/drivers/ssh.e2e.test.ts :116
await fetch(`http://127.0.0.1:${conn.port}/json`) - net phnx-labs-agi-cli-9006de7/cli/src/lib/browser/drivers/ssh.ts :2
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/ipc.test.ts :3
import * as net from 'net'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/browser/ipc.ts :1
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/port.test.ts :2
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/browser/stream.test.ts :4
import type * as net from 'net'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/byok-usage.ts :92
fetch(token: string): Promise<ByokUsageResult>; - net phnx-labs-agi-cli-9006de7/cli/src/lib/cloud/antigravity.ts :159
resp = await fetch(INTERACTIONS_URL, { - net phnx-labs-agi-cli-9006de7/cli/src/lib/cloud/cursor.ts :188
response = await fetch(`${CURSOR_API_BASE_URL}${path}`, { - net phnx-labs-agi-cli-9006de7/cli/src/lib/cloud/rush.ts :83
return fetch(url, { - net phnx-labs-agi-cli-9006de7/cli/src/lib/computer/computer-rpc.ts :16
import { createConnection, type Socket } from 'net'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/computer/ssh-tunnel.ts :21
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/daemon-webhooks.test.ts :3
import * as http from 'http'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/daemon-webhooks.ts :20
import type { Server } from 'http'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/daemon/daemon.lifecycle.test.ts :19
import * as net from 'net'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/daemon/daemon.stop.test.ts :19
import * as net from 'net'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/fleet/remote-login.ts :29
import * as http from 'http'; - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/git.test.ts :610
await simpleGit(local).fetch(); - net phnx-labs-agi-cli-9006de7/cli/src/lib/git.ts :334
await repoGit.fetch(); - net phnx-labs-agi-cli-9006de7/cli/src/lib/helper-download.ts :231
const shaRes = await fetch(shaUrl, { signal: AbortSignal.timeout(30_000) }); - net phnx-labs-agi-cli-9006de7/cli/src/lib/hosts/progress.ts :94
* Split a combined fetch (`<log bytes><marker><exit>`) back into its parts at the - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/identity/client.test.ts :5
import * as http from 'http'; - net phnx-labs-agi-cli-9006de7/cli/src/lib/identity/client.ts :106
response = await fetch(`${PHOENIX_ID_BASE}${route}`, { - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/index.bench.ts :40
* fetch (`fetch(...).then(...)`, never awaited by the caller) and the latter is - net phnx-labs-agi-cli-9006de7/cli/src/lib/linear-project-counts.ts :312
const res = await fetch(LINEAR_API, { - net (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/memory-cache.test.ts :42
const [first, second] = await Promise.all([cache.fetch('a'), cache.fetch('a')]); - net phnx-labs-agi-cli-9006de7/cli/src/lib/monitors/dispatch.ts :116
const res = await fetch(action.url, {
26 more not shown — this panel samples each group; the count above is the real total.
secrets 30
- secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/accounts.test.ts :259
tok: process.env.CLAUDE_CODE_OAUTH_TOKEN, - secrets phnx-labs-agi-cli-9006de7/cli/src/commands/exec.ts :1444
let hasKey = !!process.env.CRABBOX_TAILSCALE_AUTH_KEY; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/sessions-r2-backup.test.ts :141
const SECRET = process.env.AGENTS_TEST_R2_SECRET_ACCESS_KEY ?? ''; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/share.test.ts :86
previousShareWriteToken = process.env.SHARE_WRITE_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/teams.cloud-dispatch.test.ts :5
const originalToken = process.env.SHARE_WRITE_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/commands/testdata/session-resolver-ssh-peer.mjs :52
const hostKey = fs.readFileSync(process.env.SRP_HOST_KEY); - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/__tests__/runner.test.ts :462
const prev = process.env.CLAUDE_CODE_OAUTH_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/accounting/usage.test.ts :1122
prevMetaKey = process.env.META_API_KEY; - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/accounting/usage.ts :2757
const envKey = process.env.META_API_KEY?.trim() || process.env.MODEL_API_KEY?.trim(); - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/agent-spec/agents.ts :2482
if (process.env.META_API_KEY?.trim() || process.env.MODEL_API_KEY?.trim()) { - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/claude-account-token.test.ts :32
prevClaudeToken = process.env.CLAUDE_CODE_OAUTH_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/cloud/antigravity.test.ts :69
const prev = process.env.GEMINI_API_KEY;
show 18 more
- secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/cloud/cursor.test.ts :55
const old = process.env.CURSOR_API_KEY; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/computer/computer-rpc.test.ts :8
token: process.env.COMPUTER_HELPER_TOKEN, - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/computer/computer-rpc.ts :226
const token = process.env.COMPUTER_HELPER_TOKEN; - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/computer/ssh-tunnel.ts :573
const prevTok = process.env.COMPUTER_HELPER_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/daemon/runner.setup-token.test.ts :34
prevClaudeToken = process.env.CLAUDE_CODE_OAUTH_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/exec.test.ts :1117
prevClaudeToken = process.env.CLAUDE_CODE_OAUTH_TOKEN; - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/linear-cache.ts :51
const fromEnv = process.env.LINEAR_API_KEY?.trim(); - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/sandbox.test.ts :34
const prev = process.env.CLAUDE_CODE_OAUTH_TOKEN; - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/sandbox.ts :94
if (process.env.GH_TOKEN || process.env.GH_ENTERPRISE_TOKEN || process.env.GITHUB_TOKEN) { - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/secrets/index.ts :599
if (process.env.AGENTS_SECRETS_NO_AUTO_REKEY === '1') return; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/session/sync/r2.test.ts :51
const SECRET = process.env.AGENTS_TEST_R2_SECRET_ACCESS_KEY ?? ''; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/session/tool-index.test.ts :8
process.env.TEST_API_TOKEN = 'literal-secret-value-789'; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/share/backend.test.ts :52
const prevShareToken = process.env.SHARE_WRITE_TOKEN; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/share/config.test.ts :24
const prevEnvToken = process.env.SHARE_WRITE_TOKEN; - secrets phnx-labs-agi-cli-9006de7/cli/src/lib/traces/backend.ts :35
const envToken = (process.env['AGENTS_TRACES_WRITE_TOKEN'] ?? '').trim(); - secrets (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/traces/sync.test.ts :102
process.env.AGENTS_TRACE_FIXTURE_SECRET = 'phoenix-secret-value'; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/tests/sandbox.test.ts :301
const original = process.env.ANTHROPIC_API_KEY; - secrets (weak) phnx-labs-agi-cli-9006de7/cli/tests/setup.ts :81
delete process.env.CLAUDE_CODE_OAUTH_TOKEN;
install hooks 4
- prepare phnx-labs-agi-cli-9006de7/cli/package.json :48
npm run build - prepack phnx-labs-agi-cli-9006de7/cli/package.json :49
cp ../README.md README.md - postinstall phnx-labs-agi-cli-9006de7/cli/package.json :50
node scripts/postinstall.js - postinstall phnx-labs-agi-cli-9006de7/packages/swarmify-mirror/package.json :13
node scripts/postinstall.js
declared dependencies 32
- @homebridge/node-pty-prebuilt-multiarch@0.13.1
- @inquirer/prompts@8.5.2
- @types/proper-lockfile@4.1.4
- @xterm/headless@6.0.0
- @zed-industries/agent-client-protocol@0.4.5
- acorn@8.18.0
- age-encryption@0.3.0
- aws4fetch@1.0.20
- chalk@5.6.2
- commander@15.0.0
- croner@10.0.1
- diff@9.0.0
show 20 more
- lru-cache@11.5.2
- marked@15.0.12
- marked-terminal@7.3.0
- ora@9.4.1
- proper-lockfile@4.1.2
- shlex@3.0.0
- simple-git@3.36.0
- smol-toml@1.7.0
- unbash@4.0.5
- ws@^8.21.0
- yaml@2.9.0
- @types/diff@8.0.0
- @types/marked-terminal@6.1.1
- @types/node@26.1.0
- @types/ssh2@1.15.5
- @types/ws@^8.18.1
- ssh2@1.17.0
- tsx@4.23.0
- typescript@6.0.3
- vitest@4.1.9
clipboard 2
- clipboard shell call phnx-labs-agi-cli-9006de7/cli/src/commands/secrets.ts :3150
? [['pbcopy', []]] - clipboard shell call phnx-labs-agi-cli-9006de7/cli/src/commands/sessions-browser.ts :309
? [['pbcopy', [] as string[]]]
obfuscation 4
- dynamic require()/import() phnx-labs-agi-cli-9006de7/cli/src/lib/__tests__/manifest.test.ts :26
const { readManifest, writeManifest } = await import(${JSON.stringify(manifestPath)}); - dynamic require()/import() phnx-labs-agi-cli-9006de7/cli/src/lib/__tests__/state.test.ts :210
const { updateMeta } = await import(${JSON.stringify(modulePath)}); - dynamic require()/import() phnx-labs-agi-cli-9006de7/cli/src/lib/hooks/install.test.ts :54
const mod = await import(${JSON.stringify(modulePath)}); - dynamic require()/import() phnx-labs-agi-cli-9006de7/cli/src/lib/resource-inventory.test.ts :52
const { getVersionHomePath } = await import(${JSON.stringify(versionsPath)});
perm:untrusted 1
- untrusted (weak) phnx-labs-agi-cli-9006de7/cli/src/lib/index.bench.ts :40
* fetch (`fetch(...).then(...)`, never awaited by the caller) and the latter is