Static analysis flagged 14 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references child process execution.
dist/service-launcher.mjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/service-launcher.mjsView on unpkg · L2Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/NodePtyAdapter-CHGVwPo2.mjsView on unpkgPackage source references child process execution.
dist/service-launcher.mjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/service-launcher.mjsView on unpkg · L2Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/NodePtyAdapter-CHGVwPo2.mjsView on unpkg