hmharness agent execution layer: base tools, system prompt, sub-agent spawn, and the shared task runner that frontends (cli, web) drive.
Static analysis completed at 97.0% confidence. No malicious behavior was detected; 11 low-signal pattern(s) were surfaced and cleared.
Package source references a known benign dynamic code generation pattern.
dist/rlm-tool.jsView on unpkg · L13Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/pipeline.jsView on unpkg · L116A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/tools.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/project.jsView on unpkgThis report applies to @hmharness/agent@0.20.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references a known benign dynamic code generation pattern.
dist/rlm-tool.jsView on unpkg · L13A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/tools.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/project.jsView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/pipeline.jsView on unpkg · L116