TODOforAI CLI — create and manage tasks with tfa-cli.
No attack was identified in the inspected source. Session files are read by an explicit import feature, and the package has no automatic install hook.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. A high or critical static finding has no usable source path. These conditions do not mean that the AI confirmed malicious behavior.
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L50731Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/todoforai-cli.jsView on unpkg · L309Source appears to send environment or credential material to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L309Source executes local commands and sends command output to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L50720Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L4This report applies to @todoforai/cli@0.1.65.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L50731Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/todoforai-cli.jsView on unpkg · L309Source appears to send environment or credential material to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L309Source executes local commands and sends command output to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L50720Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L4