Checksum.ai test runtime
No confirmed malicious attack surface. Runtime capabilities activate through explicit Checksum/Playwright test execution; the manifest does not install a lifecycle hook.
Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Source mutates builtin networking, serialization, module-loading, or filesystem APIs while forwarding data to an external endpoint.
index.jsView on unpkg · L155A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
checksum-progress-reporter.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
checksum-progress-reporter.jsSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1Hardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44This report applies to @checksum-ai/runtime@4.16.7.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L155Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.jsView on unpkgPackage source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Source mutates builtin networking, serialization, module-loading, or filesystem APIs while forwarding data to an external endpoint.
index.jsView on unpkg · L155A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1Hardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L155Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
checksum-progress-reporter.jsView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
checksum-progress-reporter.jsView on unpkg