Loading npm security reports…
SPARK skills and runtime bootstrap for coding agents
No install-time malware was found, but the user-invoked dashboard exposes an unauthenticated local web API that can write agent skill files. This is a real unresolved security risk rather than confirmed malicious intent.
Package source references weak cryptographic algorithms.
skills/brainstorming/scripts/server.cjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
bin/spark-install.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
src/dashboard/server.jsView on unpkgPackage source references weak cryptographic algorithms.
skills/brainstorming/scripts/server.cjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
bin/spark-install.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
src/dashboard/server.jsView on unpkg