AI called this Suspicious at 91.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- Explicit bin writes modal assets and edits manifest.json.
- It adds web_accessible_resources with <all_urls> and sandbox pages.
Evidence against
- package.json has no install lifecycle hooks.
- Writes occur only when the user runs bodhi-js-core.
- No child-process, environment harvesting, or exfiltration found.
- Runtime fetches are SDK API/OAuth calls to configured Bodhi servers.
Behavioral surface
Supply chainHighEntropyStringsMinifiedUrlStrings
ManifestNo manifest risk signals triggered.
scanned 15 file(s), 1.32 MB of source, external domains: chromewebstore.google.com, cloud.getbodhi.app, getbodhi.app, github.com, reactjs.org, www.w3.org