Checksum.ai test runtime
No confirmed malicious attack surface was established. Playwright changes and report networking occur in the package's explicit test CLI workflow, not during npm installation or import.
Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Source mutates builtin networking, serialization, module-loading, or filesystem APIs while forwarding data to an external endpoint.
index.jsView on unpkg · L155A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
checksum-progress-reporter.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
checksum-progress-reporter.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1Hardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44This report applies to @checksum-ai/runtime@4.16.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L155Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
checksum-progress-reporter.jsView on unpkg · L1Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Source mutates builtin networking, serialization, module-loading, or filesystem APIs while forwarding data to an external endpoint.
index.jsView on unpkg · L155A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1Hardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L155Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
checksum-progress-reporter.jsView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
checksum-progress-reporter.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
checksum-progress-reporter.jsView on unpkg