TypeScript SDK and CLI for Granular - define, build, and deploy AI sandboxes
Static analysis flagged 18 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/agent-evals.jsView on unpkgPackage source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2This report applies to @granular-software/sdk@0.4.61.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/agent-evals.jsView on unpkgPackage source references dynamic require/import behavior.
dist/agent-evals.jsView on unpkg · L2