Hone AI — Enterprise SDLC Pipeline CLI
No attack was identified in the inspected source. The agent configuration change registers the package’s own MCP server in editor mode, and the inspected provider credential is sent to Anthropic’s API.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
hone-cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
hone-cli.jsView on unpkgPackage source invokes a package manager install command at runtime.
hone-cli.jsView on unpkg · L1303Package source references dynamic require/import behavior.
bin/hone-mcp.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
lib/hook-templates/pre-push.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/auto-verify.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/performance-analyzer.jsView on unpkgThis report applies to @hone-ai/cli@1.35.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L24Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L24Package ships non-JavaScript build or shell helper files.
lib/hook-templates/pre-push.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/auto-verify.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/performance-analyzer.jsView on unpkgPackage source invokes a package manager install command at runtime.
hone-cli.jsView on unpkg · L1303This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
hone-cli.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
hone-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/hone-mcp.jsView on unpkg · L6