Complaint Management UI package — atomic React components that run on the parent app's auth and API
No malicious attack surface was identified. The package is a complaint-management UI with ordinary API and user-file upload behavior.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe application configures an API client for its complaint service and applies an authentication token to that client's requests.
dist/complaint-app.jsView on unpkg · L3794File transfer is an invoked upload action: it requests a signed URL, then uploads the supplied file to it.
dist/complaint-app.jsView on unpkg · L4803A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe required stylesheet contains presentation-only CSS.
dist/style.cssView on unpkg · L1Package metadata exposes compiled UI entry points and contains only development, build, lint, and preview scripts; no install lifecycle hook is declared.
package.jsonView on unpkg · L17This report applies to @attabot/complaint-app@1.0.26.
See version security history for other recorded verdicts.
Evidence last updated: .
The application configures an API client for its complaint service and applies an authentication token to that client's requests.
dist/complaint-app.jsView on unpkg · L3794Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe required stylesheet contains presentation-only CSS.
dist/style.cssView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgFile transfer is an invoked upload action: it requests a signed URL, then uploads the supplied file to it.
dist/complaint-app.jsView on unpkg · L4803Package metadata exposes compiled UI entry points and contains only development, build, lint, and preview scripts; no install lifecycle hook is declared.
package.jsonView on unpkg · L17