Files
hermes-agent/tools
Teknium f289aae1f5 Port from aaif-goose/goose#11466: recognize Windows package-runner shims in OSV malware preflight
uvx.exe (uv's actual Windows shim) and pipx.exe bypassed the MCP OSV
malware check entirely, and backslash-qualified commands only resolved
when running under ntpath. Basename now splits on both separators;
matching stays exact (npx.cmd / uvx.exe / uvx.cmd / pipx.exe) so
lookalikes like npx.exe or npx.cmd.bak remain fail-open.
2026-09-13 20:46:22 -07:00
..