The global yorn command executes an opaque loader and compiled V8 bytecode only when the user runs the CLI. This prevents static verification of the runtime payload; no concrete malicious behavior was established.
Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgLoader dynamically inflates/constructs opaque code.
dist/load.cjsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgLoader dynamically inflates/constructs opaque code.
dist/load.cjsView on unpkg · L2