No confirmed malicious attack surface. Runtime API calls target the configured Mistral API; opt-in telemetry can export traces with the client API key.
Static reason
No blocking static signals were detected.
Trigger
User constructs the SDK and invokes an API operation; telemetry additionally requires configuration or MISTRAL_SDK_TELEMETRY.
Impact
Expected API/telemetry network traffic; no install-time execution, persistence, or unconsented harvesting found.
Mechanism
SDK HTTP client and optional OpenTelemetry exporter.
Rationale
The package is a generated Mistral API client with no install hook and no destructive, persistence, execution, or unrelated exfiltration behavior. The flagged dynamic import and environment reads support optional telemetry and are package-aligned.
Evidence
package.jsonesm/lib/http.jsesm/lib/sdks.jsesm/hooks/tracing.jsesm/extra/observability/telemetry.jsesm/lib/config.js
Network endpoints2
api.mistral.aiapi.mistral.ai/telemetry/v1/traces