Checksum.ai test runtime
Static analysis completed at 0.0% confidence. No malicious behavior was detected; 23 low-signal pattern(s) were surfaced and cleared.
Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
index.jsView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
checksum-progress-reporter.js#virtual:normalized:round1View on unpkgHardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44This report applies to @checksum-ai/runtime@5.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L129A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L129Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
index.jsView on unpkg · L129Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
index.jsView on unpkg · L129Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
index.jsView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
checksum-progress-reporter.js#virtual:normalized:round1View on unpkgHardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L129A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L129Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
index.jsView on unpkg · L129Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
index.jsView on unpkg · L129