Sato Check · Package
@goplus/agentguard
npm:@goplus/agentguard · v1.1.29 · sha256:676b5fe86064 · as of 2026-09-26
- Does it take your key? no evidence
- No private-key read found in what we read of its setup and published code — the limits say how much that was.
- No evidence line on file for this question yet.
- Does your key leave? observed
- Not observed — no planted key left during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
- We ran it with planted test keys and saw it.
- Can it move funds on its own? no evidence
- Unknown — we could not read what it exposes.
- No evidence line on file for this question yet.
- What changed? no evidence
- First profile of this subject — nothing to compare yet.
- No evidence line on file for this question yet.
Is this your project? Respond →Dispute this reading
Hosts contacted
| Host | When | Role | Evidence |
|---|---|---|---|
| agentguard.gopluslabs.io | code | other | traced |
| api.gopluslabs.io | code | other | traced |
| cdn.tailwindcss.com | code | other | traced |
| clawhub.ai | code | other | traced |
| fonts.googleapis.com | code | other | traced |
| github.com | code | registry | traced |
| json.schemastore.org | code | other | traced |
| t.me | code | other | traced |
| wa.me | code | other | traced |
| x.com | code | other | traced |
| registry.npmjs.org | install | registry | observed |
Evidence (12 lines)
- observedO-hosts2026-09-25
registry.npmjs.org was contacted during install (registry).
sandbox:obs_f140947545aaea3b
- tracedT-install-script2026-09-26
package.json runs postinstall: node dist/postinstall.js || true.
package.json
- tracedT-hosts2026-09-26
agentguard.gopluslabs.io appears in shipped code (other).
dist/cli.js
- tracedT-hosts2026-09-26
api.gopluslabs.io appears in shipped code (other).
dist/action/goplus/client.js
- tracedT-hosts2026-09-26
cdn.tailwindcss.com appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
- tracedT-hosts2026-09-26
clawhub.ai appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
- tracedT-hosts2026-09-26
fonts.googleapis.com appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
- tracedT-hosts2026-09-26
github.com appears in shipped code (registry).
dist/cli.js
- tracedT-hosts2026-09-26
json.schemastore.org appears in shipped code (other).
skills/agentguard/scripts/scan-to-sarif.js
- tracedT-hosts2026-09-26
t.me appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
- tracedT-hosts2026-09-26
wa.me appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
- tracedT-hosts2026-09-26
x.com appears in shipped code (other).
skills/agentguard/scripts/checkup-report.js
Limits
- Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
- Key egress not observed during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
- No tool inventory was available, so fund actions were not read.
- Sandbox: DNS queries made directly by the target are not logged; hosts are recorded from proxied HTTP(S) requests and CONNECTs..
- Sandbox: Code that ignores HTTP(S)_PROXY has no route out of the sandbox, so its attempts are not captured..
A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".
sato.custody/v1 · custody-1
Maintain this project? Respond to this reading
Loading sign-in…