TypeScript SDK and CLI for Granular - define, build, and deploy AI sandboxes
No confirmed malicious attack surface. Risky primitives are aligned with an SDK/CLI for Granular sandbox projects and are activated by explicit API/CLI use, not install or import.
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6Package source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2This report applies to @granular-software/sdk@0.4.49.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6Package source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2