Loading npm security reports…
SPARK skills and runtime bootstrap for coding agents
No confirmed malicious behavior was found, but the user-invoked dashboard exposes a risky unauthenticated local HTTP write primitive. The issue is best treated as a vulnerability/dual-use risk rather than malware.
Package source references weak cryptographic algorithms.
skills/brainstorming/scripts/server.cjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
bin/spark-install.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
src/dashboard/server.jsView on unpkgPackage source references weak cryptographic algorithms.
skills/brainstorming/scripts/server.cjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
bin/spark-install.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
src/dashboard/server.jsView on unpkg