`adep` 命令行工具包位:登录 / 初始化 / 本地调试 / 部署 / 数据库维护 / 云存储 / 静态托管 / 微前端组件(widget),实现见任务单 CLI-001 ~ CLI-003 与 FE-002;子路径 `@adep/cli/vite` 提供云函数 vite 插件(CLI-014)
No attack surface was identified. Network and credential operations are command-driven service functionality, and worker fetches enforce an allowlist.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L16Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L12Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/index.jsView on unpkg · L12Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L12Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L84Package source executes code through a VM context API.
dist/index.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/worker-entry.jsView on unpkgThis report applies to @adep/cli@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L16Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L12Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/index.jsView on unpkg · L12Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L12Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L84Package source executes code through a VM context API.
dist/index.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/worker-entry.jsView on unpkg