Local-first email client with IMAP sync and standalone native app
No confirmed malicious attack surface. The lifecycle hook is workspace-local; runtime mailto registration is first-party email-client behavior, not an AI-agent control-surface change.
A newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/mailx.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L11466Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/mailx-store-web/worker-bundle.jsView on unpkgPackage source references weak cryptographic algorithms.
Package source invokes a package manager install command at runtime.
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32A newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L11466Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/mailx-store-web/worker-bundle.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Package source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Package source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/mailx.jsView on unpkgPackage source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L661Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136