Static analysis flagged 14 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L63This report applies to @flotic/minitok@1.3.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Hardcoded password in src/cli/commands/auth.js
src/cli/commands/auth.jsView on unpkg · L74Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/runtime/stdio.jsView on unpkgPackage text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L63Hardcoded password in src/cli/commands/auth.js
src/cli/commands/auth.jsView on unpkg · L74Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/runtime/stdio.jsView on unpkg