Loading npm security reports…
Owner-controlled Atom agent backend: A2A transport, MLS E2E, signed data objects.
A deliberately started, externally bound server exposes unauthenticated administrative APIs. If configured with Stripe or Google credentials, a network caller can invoke those capabilities.
`dist/server.js` registers sensitive admin routes without authentication.
dist/server.jsView on unpkg`dist/server.js` registers sensitive admin routes without authentication.
dist/server.jsView on unpkg