Devflow 专项研发 Pi,基于固定版本 OMP Runtime 组装研发状态机、代码智能、设计、实现与质量门禁。
No concrete attack was identified in the inspected behavior. The postinstall script applies a narrow dependency hotfix, while Playwright agent setup is exposed through an explicit command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
src/platform-extension.tsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkgPackage source references weak cryptographic algorithms.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkg · L123A single source file combines environment access, network access, and code or shell execution; review context before blocking.
node_modules/playwright/lib/runner/index.jsView on unpkg · L864Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/playwright/lib/common/index.jsView on unpkg · L78Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
node_modules/playwright-core/lib/vite/traceViewer/assets/defaultSettingsView-Ds6CBOo0.jsView on unpkg · L165Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L552Package ships WebAssembly modules.
node_modules/playwright-core/lib/webp_codec.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
plugins/devflow-core/runtime/hooks/post_tool.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
plugins/devflow-quality/runtime/playwright/explore-host.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/tools/cli-client/channelSessions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/agents/generateAgents.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/cli/testActions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/util.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/devflow-design/extensions/devflow-design.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/devflow-quality/extensions/devflow-quality.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/doctor.tsView on unpkgThis report applies to @guanlin4924/devflow-pi@0.1.97.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkgPackage source references weak cryptographic algorithms.
node_modules/playwright-core/lib/utilsBundle.jsView on unpkg · L123Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
node_modules/playwright-core/lib/vite/traceViewer/assets/defaultSettingsView-Ds6CBOo0.jsView on unpkg · L165Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
node_modules/playwright-core/lib/coreBundle.jsView on unpkg · L552Package ships WebAssembly modules.
node_modules/playwright-core/lib/webp_codec.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
plugins/devflow-core/runtime/hooks/post_tool.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
plugins/devflow-quality/runtime/playwright/explore-host.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright-core/lib/tools/cli-client/channelSessions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/agents/generateAgents.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/cli/testActions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/playwright/lib/util.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/devflow-design/extensions/devflow-design.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
plugins/devflow-quality/extensions/devflow-quality.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/doctor.tsView on unpkgPackage source references child process execution.
src/platform-extension.tsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
node_modules/playwright/lib/runner/index.jsView on unpkg · L864Source contains an obfuscated payload loader that reconstructs and executes hidden code.
node_modules/playwright/lib/common/index.jsView on unpkg · L78