TypeScript SDK and CLI for Granular - define, build, and deploy AI sandboxes
No confirmed malicious attack surface. Network and file operations are tied to explicit SDK/CLI actions and evaluation artifacts.
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/agent-evals.jsView on unpkgPackage source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2This report applies to @granular-software/sdk@0.4.60.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/agent-evals.jsView on unpkgPackage source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2