Verified coding workflows for the terminal
LPM flags this version as an AI-agent control-surface risk. An install-time hook changes Cline's MCP configuration and installs Cline guidance. No affirmative response is required because a blank answer proceeds.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth/oauth.jsView on unpkgThis report applies to @flotic/minitok@1.4.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Package text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth/oauth.jsView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5