AI chat components and utilities for the Eight Wave Agent Studio platform. The package offers multiple entry points depending on your use case — from a drop-in web component to a framework-agnostic API client.
No malicious attack surface was identified. The package is a browser UI library with component-triggered API and icon requests.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package contains a possible secret pattern.
dist/_chunks/index.es-BJnUA_36.jsView on unpkg · L30Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L103Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1018Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D8_LwZMR.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D8_LwZMR.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CDwuCpbE.jsView on unpkgHardcoded password in dist/_chunks/web-Dzr6HJ14.js
dist/_chunks/web-Dzr6HJ14.jsView on unpkg · L7027This report applies to @8wave/ai-elements@0.110.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L103Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1018Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D8_LwZMR.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D8_LwZMR.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CDwuCpbE.jsView on unpkgHardcoded password in dist/_chunks/web-Dzr6HJ14.js
dist/_chunks/web-Dzr6HJ14.jsView on unpkg · L7027Package contains a possible secret pattern.
dist/_chunks/index.es-BJnUA_36.jsView on unpkg · L30