npm JavaScript analyzed 0.76.0

claude-code-session-manager

v0.76.0
npm

Local cockpit for the Claude Code CLI — multi-tab terminal, full config surface, scheduler, voice dictation, and live observability.

maintainer
bilkobibitkov
licence
MIT
first seen
2026-08-12
last seen
2026-09-02
releases · 30d
8
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities 0 tools
transport stdio · http counts 0 tools · 0 res · 0 prompts permission surface via code analysis

No tools enumerated yet for this server.

skills & danger signals npm-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed v0.76.0 · analyzer v33 · 2w ago

skills & prompt files 40

danger signals3

  • dynamic code execution new Function() package/dist/vad/ort-wasm-simd-threaded.asyncify.mjs :49 estructorsRef, args) {\n ${k}\n }`;c=(new Function(Object.keys(h),k))(...Object.values(h));k=`methodCaller<(${e.map(m=>m.name)}) => ${d.name}>`;return Pg(Object.defineProperty(c,"name",{value:k}))}f
  • dynamic code execution new Function() package/dist/vad/ort-wasm-simd-threaded.jsep.mjs :51 estructorsRef, args) {\n ${l}\n }`;d=(new Function(Object.keys(k),l))(...Object.values(k));l=`methodCaller<(${e.map(n=>n.name)}) => ${c.name}>`;return Ef(Object.defineProperty(d,"name",{value:l}))}f
  • dynamic code execution new Function() package/dist/vad/ort-wasm-simd-threaded.jspi.mjs :51 estructorsRef, args) {\n ${l}\n }`;c=(new Function(Object.keys(h),l))(...Object.values(h));l=`methodCaller<(${e.map(n=>n.name)}) => ${d.name}>`;return Ie(Object.defineProperty(c,"name",{value:l}))}f
code evidence v0.76.0 · npm-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 417

filesystem 186

  • fs package/dist/vad/ort-wasm-simd-threaded.asyncify.mjs :4 if(l){var fs=require("fs");ia.startsWith("file:")&&(ja=require("path").dirname(require("url").fileURLToPath(ia))+"/");la=a=>{a=ma(a)?new URL(a):a;return fs.readFileSync(a)};ka=async a=>{a=ma(a)?new UR
  • fs package/dist/vad/ort-wasm-simd-threaded.jsep.mjs :7 if(h){var fs=require("fs");ja.startsWith("file:")&&(ka=require("path").dirname(require("url").fileURLToPath(ja))+"/");ma=a=>{a=na(a)?new URL(a):a;return fs.readFileSync(a)};la=async a=>{a=na(a)?new UR
  • fs package/dist/vad/ort-wasm-simd-threaded.jspi.mjs :3 if(k){var fs=require("fs");fa.startsWith("file:")&&(ha=require("path").dirname(require("url").fileURLToPath(fa))+"/");ja=a=>{a=ka(a)?new URL(a):a;return fs.readFileSync(a)};ia=async a=>{a=ka(a)?new UR
  • fs package/dist/vad/ort-wasm-simd-threaded.mjs :3 if(m){var fs=require("fs");ea.startsWith("file:")&&(fa=require("path").dirname(require("url").fileURLToPath(ea))+"/");ia=a=>{a=ja(a)?new URL(a):a;return fs.readFileSync(a)};ha=async a=>{a=ja(a)?new UR
  • fs (weak) package/scripts/lib/activeSessions.cjs :11 const fs = require('node:fs');
  • fs (weak) package/scripts/lib/watchdogHelpers.cjs :6 const fs = require('node:fs');
  • fs (weak) package/scripts/postinstall.cjs :15 const fs = require('node:fs');
  • fs (weak) package/scripts/scheduler-mcp-server.cjs :24 const fsp = require('node:fs/promises');
  • fs (weak) package/src/main/__tests__/activeIndexMerge.test.cjs :20 const fsp = require('node:fs/promises');
  • fs (weak) package/src/main/__tests__/agentLibrary.test.cjs :11 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/agentModelResolve.test.cjs :12 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/bilkoHost-integration.test.cjs :6 const fs = require('node:fs');
show 28 more
  • fs (weak) package/src/main/__tests__/chat-cancel-terminal.test.cjs :25 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/chat-dead-channels.test.cjs :17 const fs = require('fs');
  • fs (weak) package/src/main/__tests__/chat-mcp-consent-notice.test.cjs :18 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/chatRunner-epic-worktree-execcwd.test.cjs :16 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/config-readText-bounded.test.cjs :13 const fsp = require('node:fs/promises');
  • fs (weak) package/src/main/__tests__/crossProjectFeedback.test.cjs :17 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/crossProjectFeedbackRoutes.test.cjs :25 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/develop-skill-failure-modes.test.cjs :20 const fs = require('fs');
  • fs (weak) package/src/main/__tests__/dod-batchkey.test.cjs :12 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/dod-drain-hook.test.cjs :19 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/dod-report.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/dod-reverify.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/epicContextDigest.test.cjs :13 const fsp = require('node:fs/promises');
  • fs (weak) package/src/main/__tests__/epicMint.test.cjs :12 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/epicStatusMirror.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/exchanges.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/exchangesPromptId.test.cjs :13 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/flatPrdTickSweep.test.cjs :32 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/health-tick-liveness.test.cjs :16 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/heapSnapshot.test.cjs :13 const fsp = require('node:fs/promises');
  • fs (weak) package/src/main/__tests__/historyAggregatorIntraday.test.cjs :13 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/historyDashboard.test.cjs :11 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/historyRollup.test.cjs :13 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/kg-augment.test.cjs :22 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/opsErrorLog.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/prd-group-allocator.test.cjs :18 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/prdAdminRoutes.test.cjs :14 const fs = require('node:fs');
  • fs (weak) package/src/main/__tests__/prdCreate.test.cjs :13 const fs = require('node:fs');

146 more not shown — this panel samples each group; the count above is the real total.

shell / exec 43

  • shell package/bin/cli.cjs :6 const { spawn } = require('node:child_process');
  • shell (weak) package/scripts/lib/watchdogHelpers.cjs :207 const { spawn } = require('node:child_process');
  • shell (weak) package/scripts/postinstall.cjs :14 const { spawnSync } = require('node:child_process');
  • shell (weak) package/src/main/__tests__/chat-exit-close-race.test.cjs :19 * This test mocks node:child_process.spawn so it can deterministically
  • shell (weak) package/src/main/__tests__/prdCreate.test.cjs :18 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/__tests__/pty-epic-worktree-spawn-cwd.test.cjs :81 test('spawn() launches the shell at the Epic worktree dir when one is recorded, while cwd itself stays the project cwd', () => {
  • shell (weak) package/src/main/__tests__/runVerify-transcript-commit-evidence.test.cjs :22 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/__tests__/runVerify.test.cjs :27 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/__tests__/scheduler-committed-in-window.test.cjs :14 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/__tests__/scheduler-investigation-prompt.test.cjs :14 const { execFileSync } = require('node:child_process');
  • shell package/src/main/bilkoHost.cjs :36 const { execFileSync } = require('node:child_process');
  • shell package/src/main/chatRunner.cjs :45 const { spawn } = require('node:child_process');
show 28 more
  • shell package/src/main/docEdit.cjs :18 const { spawn } = require('node:child_process');
  • shell package/src/main/git.cjs :5 * fresh for our conventions: argv-array spawn (never shell:true), validatePath
  • shell package/src/main/health.cjs :11 const { execFileSync } = require('node:child_process');
  • shell package/src/main/index.cjs :2 const { spawn, execFile, execFileSync } = require('node:child_process');
  • shell package/src/main/ipcSchemas.cjs :837 // watchers:add runs `spawn(command, { shell: true })` — second-highest blast
  • shell (weak) package/src/main/lib/__tests__/delegationReadiness.test.cjs :372 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/epicWorktreeBoot.test.cjs :90 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/epicWorktreeMerge.test.cjs :21 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/epicWorktreeMint.test.cjs :22 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/gitWorktree.test.cjs :18 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/gitWorktreeSalvage.test.cjs :16 const { execFileSync } = require('node:child_process');
  • shell (weak) package/src/main/lib/__tests__/jobWorktree.test.cjs :20 const { execFileSync } = require('node:child_process');
  • shell package/src/main/lib/childWithLog.cjs :50 const { spawn } = require('node:child_process');
  • shell package/src/main/lib/classifyPromptTicket.cjs :18 const { spawn } = require('node:child_process');
  • shell package/src/main/lib/claudeBin.cjs :8 * "claude" so spawn() can still try PATH lookup.
  • shell package/src/main/lib/credentials.cjs :7 const { spawn, execFileSync } = require('node:child_process');
  • shell package/src/main/lib/definitionOfDone.cjs :14 const { spawn, spawnSync } = require('node:child_process');
  • shell package/src/main/lib/delegationReadiness.cjs :22 const { spawn } = require('node:child_process');
  • shell package/src/main/lib/gitWorktree.cjs :56 const { execFile } = require('node:child_process');
  • shell package/src/main/lib/loadGate.cjs :27 const { execFileSync } = require('node:child_process');
  • shell package/src/main/lib/openExternalApp.cjs :13 const { execFileSync, spawn } = require('node:child_process');
  • shell package/src/main/lib/personaImportHealth.cjs :22 const { execFileSync } = require('node:child_process');
  • shell package/src/main/lib/runClaudeP.cjs :17 const { spawn } = require('node:child_process');
  • shell package/src/main/mcpStatus.cjs :12 const { spawn } = require('node:child_process');
  • shell package/src/main/projectBrief.cjs :23 const { spawn } = require('node:child_process');
  • shell package/src/main/pty.cjs :84 spawn({ tabId, cwd, cols = 120, rows = 30 }) {
  • shell package/src/main/runVerify.cjs :39 const { execFileSync } = require('node:child_process');
  • shell package/src/main/scheduler.cjs :51 const { execFile, execFileSync } = require('node:child_process');

3 more not shown — this panel samples each group; the count above is the real total.

network 18

  • net package/dist/assets/index-B_4PNh9T.js :2 (r){if(r.ep)return;r.ep=!0;const l=t(r);fetch(r.href,l)}})();function Mb(i){return i&&i.__esModule&&Object.prototype.hasOwnProperty.call(i,"default")?i.default:i}var Bv={exports:{}},Yp={},Gv={exports:
  • net package/dist/assets/json.worker-leyajbqV.js :58 ypeof fetch<"u"&&(Uo=function(t){return fetch(t).then(e=>e.text())});class V1{constructor(e,n){this._ctx=e,this._languageSettings=n.languageSettings,this._languageId=n.languageId,this._languageService
  • net package/dist/assets/whisperWorker-Dbia1OpC.js :5 ,b.onerror=g,b.send(null)});var f=await fetch(u,{credentials:"same-origin"});if(f.ok)return f.arrayBuffer();throw Error(f.status+" : "+f.url)}}var h,_,p,w,v,y,M=console.log.bind(console),T=console.err
  • net package/dist/vad/ort-wasm-simd-threaded.asyncify.mjs :5 b.send(null);return new Uint8Array(b.response)}),ka=async a=>{if(ma(a))return new Promise((c,d)=>{var e=new XMLHttpRequest;e.open("GET",a,!0);e.responseType="arraybuffer";e.onload=()=>{200==e.status||
  • net package/dist/vad/ort-wasm-simd-threaded.jsep.mjs :8 b.send(null);return new Uint8Array(b.response)}),la=async a=>{if(na(a))return new Promise((d,c)=>{var e=new XMLHttpRequest;e.open("GET",a,!0);e.responseType="arraybuffer";e.onload=()=>{200==e.status||
  • net package/dist/vad/ort-wasm-simd-threaded.jspi.mjs :4 b.send(null);return new Uint8Array(b.response)}),ia=async a=>{if(ka(a))return new Promise((c,d)=>{var e=new XMLHttpRequest;e.open("GET",a,!0);e.responseType="arraybuffer";e.onload=()=>{200==e.status||
  • net package/dist/vad/ort-wasm-simd-threaded.mjs :4 b.send(null);return new Uint8Array(b.response)}),ha=async a=>{if(ja(a))return new Promise((d,c)=>{var e=new XMLHttpRequest;e.open("GET",a,!0);e.responseType="arraybuffer";e.onload=()=>{200==e.status||
  • net (weak) package/scripts/scheduler-mcp-server.cjs :78 res = await fetch(`http://127.0.0.1:${port}${urlPath}`, {
  • net (weak) package/src/main/__tests__/crossProjectFeedbackRoutes.test.cjs :24 const http = require('node:http');
  • net (weak) package/src/main/__tests__/prdAdminRoutes.test.cjs :18 const http = require('node:http');
  • net (weak) package/src/main/__tests__/prdCreate.test.cjs :17 const http = require('node:http');
  • net (weak) package/src/main/__tests__/scheduler-admin-routes.test.cjs :15 const http = require('node:http');
show 6 more
  • net (weak) package/src/main/lib/__tests__/localAdminHttp.test.cjs :15 const http = require('node:http');
  • net (weak) package/src/main/lib/__tests__/schedulerMcpServerHelp.test.cjs :21 const http = require('node:http');
  • net package/src/main/lib/credentials.cjs :156 const r = await fetch(OAUTH_TOKEN_URL, {
  • net package/src/main/lib/localAdminHttp.cjs :34 const http = require('node:http');
  • net package/src/main/lib/summarize.cjs :15 const https = require('node:https');
  • net package/src/main/usage.cjs :173 r = await fetch(USAGE_URL, {

secrets 1

  • secrets package/src/main/lib/summarize.cjs :33 const fromEnv = process.env.ANTHROPIC_API_KEY;

install hooks 2

  • postinstall package/package.json :36 node scripts/postinstall.cjs
  • prepublishOnly package/package.json :37 vite build

declared dependencies 49

  • @modelcontextprotocol/sdk@^1.29.0
  • @electron/rebuild@4.0.4
  • @huggingface/transformers@^4.1.0
  • @monaco-editor/react@^4.6.0
  • @opentelemetry/api@^1.9.0
  • @opentelemetry/exporter-trace-otlp-http@^0.57.0
  • @opentelemetry/resources@^1.30.0
  • @opentelemetry/sdk-trace-base@^1.30.0
  • @opentelemetry/sdk-trace-node@^1.30.0
  • @opentelemetry/semantic-conventions@^1.28.0
  • @ricky0123/vad-web@^0.0.30
  • @tiptap/extension-link@^3.23.6
show 28 more
  • @tiptap/react@^3.23.6
  • @tiptap/starter-kit@^3.23.6
  • @xterm/addon-fit@^0.10.0
  • @xterm/addon-web-links@^0.11.0
  • @xterm/xterm@^5.5.0
  • chokidar@^4.0.1
  • dockview-react@^6.6.1
  • dompurify@^3.4.8
  • electron@42.1.0
  • marked@^14.0.0
  • monaco-editor@0.55.1
  • node-pty@^1.2.0-beta.12
  • onnxruntime-web@^1.24.3
  • react-force-graph-2d@^1.29.1
  • sharp@^0.35.3
  • tiptap-markdown@^0.9.0
  • ws@^8.18.0
  • zod@^3.23.8
  • zustand@^5.0.0
  • @playwright/test@^1.59.1
  • @types/node@^22.9.0
  • @types/react@^18.3.12
  • @types/react-dom@^18.3.1
  • @types/ws@^8.5.13
  • @vitejs/plugin-react@^4.3.3
  • autoprefixer@^10.4.20
  • concurrently@^9.1.0
  • esbuild@^0.25.12

9 more not shown — this panel samples each group; the count above is the real total.

perm:untrusted 3

  • untrusted package/dist/assets/index-B_4PNh9T.js :56 p.defaultModelFetcher=void 0;const i=e=>fetch(e).then(t=>t.arrayBuffer());return Qp.defaultModelFetcher=i,Qp}var Wa={},ef={},ky;function Yf(){if(ky)return ef;ky=1,Object.defineProperty(ef,"__esModule"
  • untrusted package/dist/assets/json.worker-leyajbqV.js :58 ypeof fetch<"u"&&(Uo=function(t){return fetch(t).then(e=>e.text())});class V1{constructor(e,n){this._ctx=e,this._languageSettings=n.languageSettings,this._languageId=n.languageId,this._languageService
  • untrusted package/dist/assets/whisperWorker-Dbia1OpC.js :17 "/resolve/","/raw/");try{const s=(await fetch(t).then(n=>n.text())).match(/^oid sha256:([0-9a-f]+)$/m);return s?s[1]:null}catch{return null}});k(this,"_getBlobHash",async e=>{const t=await e.arrayBuff