Browser SDK and default widget for embedding Pluno Product Agent into customer web apps.
No confirmed attack surface. High scanner hits match the documented Pluno Product Agent embed: same-origin token fetch with cookies, host-network observation with redaction, and a minified runtime build. Those behaviors run only after a customer installs and mounts the widget or SDK.
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83The widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
dist/product-agent-widget.jsView on unpkg · L21628After init the widget patches fetch and XHR and forwards capped host-request metadata as network.batch on the Pluno session socket.
dist/product-agent-widget.jsView on unpkg · L11234After init the widget patches fetch and XHR and forwards capped host-request metadata as network.batch on the Pluno session socket.
dist/product-agent-widget.jsView on unpkg · L11547A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
package.jsonView on unpkg · L1The widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
package.jsonView on unpkg · L26The CommonJS runtime is a two-line minified bundle, which tripped a scanner analysis limit rather than hiding a second payload.
dist/product-agent-runtime.cjsView on unpkg · L1This report applies to @pluno/product-agent-web@0.1.277.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L83The widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
dist/product-agent-widget.jsView on unpkg · L21628After init the widget patches fetch and XHR and forwards capped host-request metadata as network.batch on the Pluno session socket.
dist/product-agent-widget.jsView on unpkg · L11234After init the widget patches fetch and XHR and forwards capped host-request metadata as network.batch on the Pluno session socket.
dist/product-agent-widget.jsView on unpkg · L11547A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
package.jsonView on unpkg · L1The widget POSTs the host token endpoint with credentials include after a customer embeds it, which is the scanner account-session signal.
package.jsonView on unpkg · L26The CommonJS runtime is a two-line minified bundle, which tripped a scanner analysis limit rather than hiding a second payload.
dist/product-agent-runtime.cjsView on unpkg · L1