Static analysis flagged 13 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L63This report applies to @flotic/minitok@1.3.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Hardcoded password in src/cli/commands/auth.js
src/cli/commands/auth.jsView on unpkg · L74Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L63Hardcoded password in src/cli/commands/auth.js
src/cli/commands/auth.jsView on unpkg · L74Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg