Nimbus runtime package for Cloudflare Workers, re-exported publicly through @nimbus-sh/sdk/worker.
No confirmed malicious attack surface. The flagged dynamic evaluation is a browser HMR mechanism for same-origin preview assets.
Package source references child process execution.
dist/facets/vite-dev-server.jsView on unpkg · L402Package source references dynamic code evaluation.
dist/facets/vite-dev-server.jsView on unpkg · L62Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references weak cryptographic algorithms.
public/_assets/real-vite-bundle.jsView on unpkg · L200Package source references dynamic require/import behavior.
dist/facets/wasm-swap-registry.js#virtual:normalized:round1View on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/git-bundle.generated.jsView on unpkg · L12Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/git-bundle.generated.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Package contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgThis report applies to @nimbus-sh/worker@0.2.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic code evaluation.
dist/facets/vite-dev-server.jsView on unpkg · L62Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references dynamic require/import behavior.
dist/facets/wasm-swap-registry.js#virtual:normalized:round1View on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Package contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgPackage source references child process execution.
dist/facets/vite-dev-server.jsView on unpkg · L402Package source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references weak cryptographic algorithms.
public/_assets/real-vite-bundle.jsView on unpkg · L200A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/git-bundle.generated.jsView on unpkg · L12Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/git-bundle.generated.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6