MMI Future CLI — the org dev toolbox and shared cross-IDE engine for every registry-declared MMI coding surface.
Running Hub-backed CLI commands can disclose the user's raw GitHub token to a hard-coded remote service. Vault commands can additionally pass retrieved secrets to a child process.
Source appears to send environment or credential material to an external endpoint.
dist/main.cjsView on unpkg · L53A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/main.cjsView on unpkg · L3526Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/main.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L4This report applies to @mutmutco/cli@4.3.39.
See version security history for other recorded verdicts.
Evidence last updated: .
Source appears to send environment or credential material to an external endpoint.
dist/main.cjsView on unpkg · L53A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/main.cjsView on unpkg · L3526Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/main.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L4