
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@uipath/codedagent-tool
Advanced tools
Affected versions:
A command-line tool over uipath-python
Detects Python installation and verifies required package is installed.
uip codedagent setup [options]
Options:
--force - Force re-detection of Python even if cachedExecutes the configured Python package with provided arguments.
uip codedagent exec [args...]
Options:
--interactive - enable interactive modeAll arguments are passed directly to the Python package.
The following settings are configured in the code and can be overridden via environment variables:
Default: 3.11, 3.12, 3.13
Override with PYTHON_TOOL_PYTHON_VERSIONS environment variable:
# Windows
set PYTHON_TOOL_PYTHON_VERSIONS=3.13,3.12,3.11
# Linux/macOS
export PYTHON_TOOL_PYTHON_VERSIONS=3.13,3.12,3.11
The tool uses a cache file (.codedagent-tool-cache.json) to store:
If the cached Python path no longer exists, will ask user to configure.
uip codedagent init
❌ Invalid config. Python (C:\Users\georgescu.vlad\AppData\Local\Programs\Python\Python311\python.exe) no longer exists.
Run 'uip codedagent setup' to reconfigure.
# Setup with default package (uipath-python)
uip codedagent setup
# Force re-detection
uip codedagent setup --force
# Setup with custom package via environment variable
export CLOUD_TOOL_PACKAGE_NAME=my-package
uip codedagent setup
# Run package with arguments
uip codedagent run --help
uip codedagent run command --option value
# Interactive command
uip codedagent run interactive-shell
# Override Python versions via environment variable
export PYTHON_TOOL_PYTHON_VERSIONS=3.10,3.11
uip codedagent setup
# Full configuration example
export PYTHON_TOOL_PYTHON_VERSIONS=3.10,3.11,3.12
export CLOUD_TOOL_PACKAGE_NAME=uipath-python
uip codedagent setup
uip codedagent run --version
FAQs
Build, run, deploy, and manage AI Agents.
The npm package @uipath/codedagent-tool receives a total of 548 weekly downloads. As such, @uipath/codedagent-tool popularity was classified as not popular.
We found that @uipath/codedagent-tool demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 24 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.