CLI for [TODOforAI](https://todofor.ai) — create, watch, and inspect AI-powered todos.
The CLI can retrieve and execute an unpinned shell installer from the vendor site. This is not an npm lifecycle action, but it is automatically reached during ordinary watched CLI use when the bridge is missing.
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L45108Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source downloads or fetches remote code and executes it.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/todoforai-cli.jsView on unpkg · L45097Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L9This report applies to @todoforai/cli@0.1.51.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L45108Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source downloads or fetches remote code and executes it.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/todoforai-cli.jsView on unpkg · L45097Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L9