Local desktop tool for visual screenshot-test review — CLI, runner helpers, and review UI shipped as a single package.
No confirmed malicious attack surface was found. The package starts local screenshot-review tooling on explicit CLI or configured test-run actions; accepting a screenshot can upload that image to the configured worker.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package source references child process execution.
dist/global-setup.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/global-setup.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/global-setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15386A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L15386This report applies to @cevek/screentest@0.3.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/global-setup.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/global-setup.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/global-setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15386A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L15386