AI chat components and utilities for the Eight Wave Agent Studio platform. The package offers multiple entry points depending on your use case — from a drop-in web component to a framework-agnostic API client.
No attack surface was identified. The package is a Vue chatbot UI library whose published entries render components and load icons from the public Iconify host when the app uses them.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package contains a possible secret pattern.
dist/_chunks/web-Dzr6HJ14.jsView on unpkg · L7027Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L201Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1116Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CN8mivJ9.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D0IOaETI.jsView on unpkgHardcoded password in dist/_chunks/index.es-CvfaFCuJ.js
dist/_chunks/index.es-CvfaFCuJ.jsView on unpkg · L30This report applies to @8wave/ai-elements@0.111.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package contains a possible secret pattern.
dist/_chunks/web-Dzr6HJ14.jsView on unpkg · L7027Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L201Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1116Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CN8mivJ9.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-vue/_chunks/PkStreamingMarkdown-D0IOaETI.jsView on unpkgHardcoded password in dist/_chunks/index.es-CvfaFCuJ.js
dist/_chunks/index.es-CvfaFCuJ.jsView on unpkg · L30