Headless agent package for controlling 3dverse rendering sessions programmatically (Node.js and browser compatible)
A session join fetches unpinned JavaScript from the vendor CDN and executes it. A CDN response compromise can execute code in the consuming Node or browser process.
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2390A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgThe runtime fetches JavaScript from the vendor CDN and evaluates it with Node VM or a data-URL import.
dist/index.cjsView on unpkg · L2391Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8This report applies to @3dverse/livelink-agent@0.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgThe runtime fetches JavaScript from the vendor CDN and evaluates it with Node VM or a data-URL import.
dist/index.cjsView on unpkg · L2391Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2390