Checksum.ai test runtime
Importing the main module reads package and parent environment files. Explicit CLI use can send a configured API key to its configured service endpoint; the fully bundled code also supports an environment-selected script URL.
Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L129Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgPackage source references weak cryptographic algorithms.
scripts/playwright_patches/1.52.0.jsView on unpkg · L249Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
cli.jsView on unpkg · L129Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
checksum-progress-reporter.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
checksum-progress-reporter.jsView on unpkgHardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44This report applies to @checksum-ai/runtime@5.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L148Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L129Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
cli.jsView on unpkg · L129Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
checksum-progress-reporter.js#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
checksum-progress-reporter.jsView on unpkgHardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L148Package source references weak cryptographic algorithms.
scripts/playwright_patches/1.52.0.jsView on unpkg · L249