AI Agent Governance CLI — evaluate tool calls against rules, block dangerous operations, and surface blocked commands
A global npm install automatically deletes user-level ssg executables and registers a persistent tracking canary. It transmits a machine-derived fingerprint without an interactive consent step.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cleanup-globals.cjsView on unpkgPackage source references dynamic require/import behavior.
bin/cleanup-globals.cjsView on unpkg · L5Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/ssg.cjsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ssg.cjsView on unpkgThis report applies to @sigmashake/ssg@1.1.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L25A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/cleanup-globals.cjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cleanup-globals.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/ssg.cjsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ssg.cjsView on unpkg