Verified coding workflows for the terminal
Static analysis completed at 97.0% confidence. No malicious behavior was detected; 25 low-signal pattern(s) were surfaced and cleared.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/workspace/isolation.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/auth/oauth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/pipeline/check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/gui-run.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/mcp-client.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/auth/service-account.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/server-config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/update-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcp/cline-integration.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/entitlement/online.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/cli/gui-commands.jsView on unpkgThis report applies to @flotic/minitok@1.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Package text addresses the security reviewer or scanner and tries to influence the review outcome.
README.mdView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/workspace/isolation.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/auth/oauth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/pipeline/check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/gui-run.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/agent/mcp-client.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/auth/service-account.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cli/commands/server-config.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/core/update-check.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcp/cline-integration.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/entitlement/online.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/cli/gui-commands.jsView on unpkgPackage contains a possible secret pattern.
src/cli/commands/auth.jsView on unpkg · L108Package source references dynamic require/import behavior.
bin/minitok.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
src/llm/provider.jsView on unpkg · L5