Running the yorn command executes opaque loader code and compiled V8 bytecode. Interactive use also documents an automatic global self-update path; no install-time attack was established.
Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe package ships a 15.5 MB compiled V8 bytecode artifact whose behavior is not source-auditable.
README.mdView on unpkg · L74Documentation states interactive startup can open a terminal and globally reinstall the package.
README.mdView on unpkg · L42Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe package ships a 15.5 MB compiled V8 bytecode artifact whose behavior is not source-auditable.
README.mdView on unpkg · L74Documentation states interactive startup can open a terminal and globally reinstall the package.
README.mdView on unpkg · L42