Browser SDK and default widget for embedding Pluno Product Agent into customer web apps.
No concrete attack was identified. Authentication, preference mutations, diagnostics, and browser tool execution fit the SDK's initialized agent functionality.
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L122Widget feature mutations check the active profile's capabilities before changing preferences.
dist/product-agent-widget.jsView on unpkg · L1209Widget authentication uses caller-configured tokens or a token endpoint; browser cookie domain rules apply to its authenticated request.
dist/product-agent-widget.jsView on unpkg · L21761Widget authentication uses caller-configured tokens or a token endpoint; browser cookie domain rules apply to its authenticated request.
dist/product-agent-widget.jsView on unpkg · L13920A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe manifest has no registry install lifecycle hooks or runtime self-dependency.
package.jsonView on unpkg · L26The CommonJS runtime implements session state and dispatches session navigation through its adapter.
dist/product-agent-runtime.cjsView on unpkg · L1This report applies to @pluno/product-agent-web@0.1.310.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/product-agent-widget.jsView on unpkg · L122Widget feature mutations check the active profile's capabilities before changing preferences.
dist/product-agent-widget.jsView on unpkg · L1209Widget authentication uses caller-configured tokens or a token endpoint; browser cookie domain rules apply to its authenticated request.
dist/product-agent-widget.jsView on unpkg · L21761Widget authentication uses caller-configured tokens or a token endpoint; browser cookie domain rules apply to its authenticated request.
dist/product-agent-widget.jsView on unpkg · L13920A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/product-agent-runtime.cjs#virtual:string-array:round1View on unpkgThe manifest has no registry install lifecycle hooks or runtime self-dependency.
package.jsonView on unpkg · L26The CommonJS runtime implements session state and dispatches session navigation through its adapter.
dist/product-agent-runtime.cjsView on unpkg · L1