CLI и AI-агент городского округа Йошкар-Ола.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio · http counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
no tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v0.2.69 · analyzer v17 · 1d ago
skills & prompt files 12
- skillpackage/skills/browser-agent/SKILL.md
- skillpackage/skills/domru-intercom/SKILL.md
- skillpackage/skills/education/SKILL.md
- skillpackage/skills/geo/SKILL.md
- skillpackage/skills/local-files/SKILL.md
- skillpackage/skills/local-model/SKILL.md
- skillpackage/skills/open-data/SKILL.md
- skillpackage/skills/personal-docs/SKILL.md
- skillpackage/skills/reports/SKILL.md
- skillpackage/skills/ufanet-intercom/SKILL.md
- skillpackage/skills/user-skills/SKILL.md
- skillpackage/skills/yandex-services/SKILL.md
danger signals1
- dynamic code executionnew Function()package/src/cli.js:20027
const value = await page.evaluate(new Function("return (" + params.script + ")"));
evidence-backed
findings quoted directly from the published source artifact — not inferred
filesystem 2
- fs package/bin/postinstall.js :4
import { copyFileSync, existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs"; - fs package/src/cli.js :2
import { createWriteStream, existsSync, mkdirSync, readFileSync, readdirSync } from "node:fs";
shell / exec 2
- shell package/bin/postinstall.js :2
import { spawn } from "node:child_process"; - shell package/src/cli.js :1
import { execFile, spawn } from "node:child_process";
network 2
- net package/bin/postinstall.js :146
const response = await fetch(url, { signal: controller.signal }); - net package/src/cli.js :3
import { createServer } from "node:http";
secrets 1
- secrets package/src/cli.js :1174
const openai = Boolean(process.env.OPENAI_API_KEY || secrets.openai?.apiKey);
install hooks 1
- postinstall package/package.json :19
node --no-warnings bin/postinstall.js
declared dependencies 1
- qrcode@^1.5.4