# 使用 Homebrew 安装 imagejs

查看 imagejs 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:imagejs
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install imagejs
```

  证据: local Homebrew formula metadata

## 软件包事实

- **软件包键:** brew:imagejs
- **软件包管理器:** Homebrew
- **版本:** 0.7.2
- **来源摘要:** Tool to hide JavaScript inside valid image files
- **主页:** <https://github.com/jklmnn/imagejs>
- **仓库:** <https://github.com/jklmnn/imagejs>
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- imagejs (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 0.7.2
## 项目历史与用法

imagejs is a small proof-of-concept command-line tool for packaging JavaScript into files that remain valid image files. The README presents it as a way to create image files that can execute JavaScript and explicitly connects the idea to extending XSS vulnerabilities.

### 项目历史

The project appeared on GitHub in 2014 and credits Ajin Abraham's work on GIFs serving JavaScript as the idea that inspired the C implementation. The README says imagejs added bitmap support, and the changelog shows later support for GIF injection, BMP injection, WebP injection, and additional output formats.

### 采用历史

imagejs remained a niche security package rather than a broad media utility. GitHub repository metadata shows far more stars than package-manager breadth, and the input metadata lists Homebrew as the only package-manager mapping for this batch.

### 使用方式

Users run imagejs with an output type and a JavaScript file, producing an image-like file named after the input. The README documents BMP, GIF, WebP, PNM, and PGF outputs, a line-viewable BMP mode, and injection into existing GIF files.

### 为什么软件包爱好者会关心

The package is interesting because it lives at the boundary between file-format polyglots and web security demonstrations. It is not a general steganography suite; it is a compact package for showing how MIME assumptions, image upload policies, and script execution contexts can collide.

### 时间线

- 2014: GitHub repository is created.
- 0.4.1: GIF, BMP, WebP, PNM, and PGF output support is documented in the changelog.
- 0.5.0: GIF injection support is added.
- 0.6.0: BMP injection support is added.
- 0.7.0: WebP injection support is added.

### Related projects

- The README names Ajin Abraham's GIF/JavaScript work as the source idea. Conceptually, imagejs is related to polyglot-file demos, browser XSS testing, and image steganography tools, although its stated goal is executable JavaScript-in-image proof of concept rather than secret-message hiding.

### 来源

- Project README, changelog, GitHub repository metadata, GitHub tags, and Homebrew formula metadata.


## 安全说明

broad file, network, media, or database tool signal.

- **Geiger 风险:** blue / 中
- broad file, network, media, or database tool signal


## Combined YAML source

View the package source record on GitHub. [combined/imagejs.yml](https://github.com/mxcl/pkgdb/blob/main/combined/imagejs.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
