TypeScript SDK and CLI for Granular - define, build, and deploy AI sandboxes
Static analysis completed at 0.0% confidence. No malicious behavior was detected; 22 low-signal pattern(s) were surfaced and cleared.
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent-evals.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent-evals.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgThis report applies to @granular-software/sdk@0.4.62.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
dist/cli/index.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli/index.jsView on unpkg · L6Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli/index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli/index.jsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli/index.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli/index.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent-evals.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent-evals.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkg