No install-time attack surface was confirmed. On explicit yorn execution, an obfuscated loader can execute the shipped opaque bytecode for a terminal coding agent.
Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgOpaque V8 bytecode is shipped as dist/yorn.jsc, limiting direct behavioral audit.
README.mdView on unpkg · L78Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgOpaque V8 bytecode is shipped as dist/yorn.jsc, limiting direct behavioral audit.
README.mdView on unpkg · L78