No confirmed malicious attack surface. The opaque bytecode is reached only through the user-invoked CLI, with no install-time execution.
Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe CLI entrypoint is an obfuscated dynamic Function loader.
package.jsonView on unpkg · L6The CLI entrypoint is an obfuscated dynamic Function loader.
dist/load.cjsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe CLI entrypoint is an obfuscated dynamic Function loader.
package.jsonView on unpkg · L6The CLI entrypoint is an obfuscated dynamic Function loader.
dist/load.cjsView on unpkg · L2