Yorn terminal AI coding agent CLI
On interactive execution, the CLI checks a remote update source and can invoke a package manager to globally install the package name returned by that response. This permits remote control of code installed on the user system.
Package contains a critical-looking secret pattern.
dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.mdView on unpkg · L30AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.mdView on unpkg · L30A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/yorn.cjsView on unpkg · L22Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgHardcoded password in dist/skills/anthropic-cybersecurity-skills/securing-container-registry-with-harbor/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/securing-container-registry-with-harbor/scripts/agent.pyView on unpkg · L172AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L47AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L53AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.mdView on unpkg · L213AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.mdView on unpkg · L229Hardcoded password in dist/skills/anthropic-cybersecurity-skills/implementing-aes-encryption-for-data-at-rest/scripts/process.py
dist/skills/anthropic-cybersecurity-skills/implementing-aes-encryption-for-data-at-rest/scripts/process.pyView on unpkg · L320Hardcoded password in dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.pyView on unpkg · L242Hardcoded password in dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.pyView on unpkg · L280Hardcoded password in dist/skills/anthropic-cybersecurity-skills/exploiting-active-directory-with-bloodhound/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/exploiting-active-directory-with-bloodhound/scripts/agent.pyView on unpkg · L68Hardcoded password in dist/skills/anthropic-cybersecurity-skills/implementing-zero-knowledge-proof-for-authentication/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/implementing-zero-knowledge-proof-for-authentication/scripts/agent.pyView on unpkg · L85Hardcoded password in dist/skills/anthropic-cybersecurity-skills/performing-cryptographic-audit-of-application/scripts/process.py
dist/skills/anthropic-cybersecurity-skills/performing-cryptographic-audit-of-application/scripts/process.pyView on unpkg · L281Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/yorn.cjsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/yorn.cjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/yorn.cjsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
dist/yorn.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/yorn.cjsView on unpkg · L20A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/yorn.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/yorn.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/yorn.cjsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/yorn.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/yorn.cjsView on unpkgAWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L57AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L85Package contains a critical-looking secret pattern.
dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.mdView on unpkg · L30AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-compromised-cloud-credentials/references/api-reference.mdView on unpkg · L30A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/yorn.cjsView on unpkg · L22Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgAWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L47AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L53AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.mdView on unpkg · L213AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/SKILL.mdView on unpkg · L229Hardcoded password in dist/skills/anthropic-cybersecurity-skills/implementing-aes-encryption-for-data-at-rest/scripts/process.py
dist/skills/anthropic-cybersecurity-skills/implementing-aes-encryption-for-data-at-rest/scripts/process.pyView on unpkg · L320Hardcoded password in dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.pyView on unpkg · L242Hardcoded password in dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/deploying-active-directory-honeytokens/scripts/agent.pyView on unpkg · L280Hardcoded password in dist/skills/anthropic-cybersecurity-skills/exploiting-active-directory-with-bloodhound/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/exploiting-active-directory-with-bloodhound/scripts/agent.pyView on unpkg · L68Hardcoded password in dist/skills/anthropic-cybersecurity-skills/implementing-zero-knowledge-proof-for-authentication/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/implementing-zero-knowledge-proof-for-authentication/scripts/agent.pyView on unpkg · L85Hardcoded password in dist/skills/anthropic-cybersecurity-skills/performing-cryptographic-audit-of-application/scripts/process.py
dist/skills/anthropic-cybersecurity-skills/performing-cryptographic-audit-of-application/scripts/process.pyView on unpkg · L281Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/yorn.cjsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/yorn.cjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/yorn.cjsView on unpkg · L20Source reaches cloud instance metadata or link-local credential endpoints.
dist/yorn.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/yorn.cjsView on unpkg · L20A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/yorn.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/yorn.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/yorn.cjsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/yorn.cjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/yorn.cjsView on unpkgHardcoded password in dist/skills/anthropic-cybersecurity-skills/securing-container-registry-with-harbor/scripts/agent.py
dist/skills/anthropic-cybersecurity-skills/securing-container-registry-with-harbor/scripts/agent.pyView on unpkg · L172AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L57AWS access key ID in dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.md
dist/skills/anthropic-cybersecurity-skills/detecting-aws-credential-exposure-with-trufflehog/references/api-reference.mdView on unpkg · L85