Complaint Management UI package — atomic React components that run on the parent app's auth and API
No attack was identified in the inspected source. The API client sends its token to its configured API base URL.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe library uses an API base URL for its complaint service and allows the caller to configure it.
dist/complaint-app.jsView on unpkg · L3794The request interceptor sends the selected token as a bearer credential with API requests.
dist/complaint-app.jsView on unpkg · L3812A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe required stylesheet excerpt contains component presentation rules.
dist/style.cssView on unpkg · L1package.json defines development and build scripts but no install lifecycle hook.
package.jsonView on unpkg · L21This report applies to @attabot/complaint-app@1.0.34.
See version security history for other recorded verdicts.
Evidence last updated: .
The library uses an API base URL for its complaint service and allows the caller to configure it.
dist/complaint-app.jsView on unpkg · L3794The request interceptor sends the selected token as a bearer credential with API requests.
dist/complaint-app.jsView on unpkg · L3812Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe required stylesheet excerpt contains component presentation rules.
dist/style.cssView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgpackage.json defines development and build scripts but no install lifecycle hook.
package.jsonView on unpkg · L21