Local-first, agent-friendly Markdown knowledge base with a cross-platform CLI and web editor
Static analysis flagged 30 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package contains a critical-looking secret pattern.
dist/lib-B82GtN9K.mjsView on unpkg · L39Package source executes code through a VM context API.
dist/lib-B82GtN9K.mjsView on unpkg · L1Package source references child process execution.
dist/open-browser-xN9OlX1t.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/open-browser-xN9OlX1t.mjsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
dist/chunk-5QMZ5MUS-C5NTf5Rj.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/native/index.jsView on unpkgPackage source references dynamic require/import behavior.
dist/native/index.jsView on unpkg · L5Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/public/assets/ku-TR-6OUDTVRD-CKCYZmQ1.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/js-exec-VXN6TZ7U-Ds5SsewK.mjsView on unpkg · L28Package ships native binary artifacts.
dist/native/native-config.linux-arm64-musl.nodeView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/dist-bundle-EXrl9_Zm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dist-bundle-EXrl9_Zm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WRU74C26-BESBlKtm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZIRB5QZD-B2znOhor.mjsView on unpkgGoogle API key in dist/public/assets/chunk-ZUYEQ4TG-DLAN927O.js
dist/public/assets/chunk-ZUYEQ4TG-DLAN927O.jsView on unpkg · L1Package contains a critical-looking secret pattern.
dist/lib-B82GtN9K.mjsView on unpkg · L39Package source executes code through a VM context API.
dist/lib-B82GtN9K.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/public/assets/ku-TR-6OUDTVRD-CKCYZmQ1.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/js-exec-VXN6TZ7U-Ds5SsewK.mjsView on unpkg · L28Package ships native binary artifacts.
dist/native/native-config.linux-arm64-musl.nodeView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/dist-bundle-EXrl9_Zm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dist-bundle-EXrl9_Zm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-WRU74C26-BESBlKtm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunk-ZIRB5QZD-B2znOhor.mjsView on unpkgGoogle API key in dist/public/assets/chunk-ZUYEQ4TG-DLAN927O.js
dist/public/assets/chunk-ZUYEQ4TG-DLAN927O.jsView on unpkg · L1Package source references child process execution.
dist/open-browser-xN9OlX1t.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/open-browser-xN9OlX1t.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/src-C8z0M4Ib.mjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
dist/chunk-5QMZ5MUS-C5NTf5Rj.mjsView on unpkg · L1Package source references dynamic require/import behavior.
dist/native/index.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/native/index.jsView on unpkg