pkg.soopen package index

brew / 排名 13551

使用 Homebrew 安装 imagejs

查看 imagejs 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install imagejs

local Homebrew formula metadata

概览

软件包摘要

Tool to hide JavaScript inside valid image files

命令和别名

  • imagejs

历史

项目历史与用法

imagejs is a small proof-of-concept command-line tool for packaging JavaScript into files that remain valid image files. The README presents it as a way to create image files that can execute JavaScript and explicitly connects the idea to extending XSS vulnerabilities.

项目历史

The project appeared on GitHub in 2014 and credits Ajin Abraham's work on GIFs serving JavaScript as the idea that inspired the C implementation. The README says imagejs added bitmap support, and the changelog shows later support for GIF injection, BMP injection, WebP injection, and additional output formats.

采用历史

imagejs remained a niche security package rather than a broad media utility. GitHub repository metadata shows far more stars than package-manager breadth, and the input metadata lists Homebrew as the only package-manager mapping for this batch.

使用方式

Users run imagejs with an output type and a JavaScript file, producing an image-like file named after the input. The README documents BMP, GIF, WebP, PNM, and PGF outputs, a line-viewable BMP mode, and injection into existing GIF files.

为什么软件包爱好者会关心

The package is interesting because it lives at the boundary between file-format polyglots and web security demonstrations. It is not a general steganography suite; it is a compact package for showing how MIME assumptions, image upload policies, and script execution contexts can collide.

时间线

  • 2014: GitHub repository is created.
  • 0.4.1: GIF, BMP, WebP, PNM, and PGF output support is documented in the changelog.
  • 0.5.0: GIF injection support is added.
  • 0.6.0: BMP injection support is added.
  • 0.7.0: WebP injection support is added.

Related projects

  • The README names Ajin Abraham's GIF/JavaScript work as the source idea. Conceptually, imagejs is related to polyglot-file demos, browser XSS testing, and image steganography tools, although its stated goal is executable JavaScript-in-image proof of concept rather than secret-message hiding.

来源

  • Project README, changelog, GitHub repository metadata, GitHub tags, and Homebrew formula metadata.

安全态势

风险级别:blue

broad file, network, media, or database tool signal.

风险分类器

blue 风险 · 中 置信度 · tool

原因

  • broad file, network, media, or database tool signal

信号

  • text:image

安装行为

  • 未记录 Homebrew bottle 元数据。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

可执行文件

已安装的可执行文件

命令类型暴露范围备注
imagejs可执行文件已索引可执行文件从本地可执行文件索引发现。

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-08-03
管理器版本0.7.2
管理器更新时间
本地数据未知
上游不可用
检测到的最新版本未检测到
  • OK没有生成新鲜度警告。

安装元数据

软件包元数据

软件包键brew:imagejs
版本0.7.2
软件包管理器Homebrew
主页https://github.com/jklmnn/imagejs
仓库https://github.com/jklmnn/imagejs
Bottle未记录
服务未声明

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • pkg.so package database
  • pkgdb category and tag curation