No confirmed malicious attack surface. The install hook performs package-aligned license validation, and runtime code is static Solid icon components.
Static reason
One or more suspicious static signals were detected.
Trigger
npm install runs preinstall; application import renders icons
Impact
CENTRAL_LICENSE_KEY is sent to the vendor license endpoint if present; no evidence of exfiltration beyond license validation.
Mechanism
license check plus SVG component exports
Rationale
The lifecycle network/env behavior is explained by license enforcement and is limited to a package-aligned endpoint. Source inspection did not find malicious execution, persistence, broad credential access, destructive behavior, or unconsented AI-agent control-surface mutation.
Evidence
package.jsonlicense-check.jsindex.jsxCentralIconBase.tsxIconBluetooth/index.tsxREADME.mdskills/central-icons-solid/SKILL.md
Network endpoints1
centralicons.com/license/check