CLI for [TODOforAI](https://todofor.ai) — create, watch, and inspect AI-powered todos.
A configured API destination can receive an existing legacy credential through the unscoped credential fallback. This establishes conditional credential exposure, but no confirmed malicious attack.
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L46773Source appears to send environment or credential material to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L309Source executes local commands and sends command output to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L46762Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source downloads or fetches remote code and executes it.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L4This report applies to @todoforai/cli@0.1.62.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/todoforai-cli.jsView on unpkg · L46773Source appears to send environment or credential material to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L309Source executes local commands and sends command output to an external endpoint.
dist/todoforai-cli.jsView on unpkg · L46762Source appears to collect browser login credentials for exfiltration.
dist/todoforai-cli.jsView on unpkg · L309Source downloads or fetches remote code and executes it.
dist/todoforai-cli.jsView on unpkg · L309Source passes code obtained from a remote response into a dynamic execution sink.
dist/todoforai-cli.jsView on unpkg · L309Package source references child process execution.
dist/todoforai-cli.jsView on unpkg · L1919Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/todoforai-cli.jsView on unpkg · L309Source exposes local file and command tools to a remote model endpoint.
dist/todoforai-cli.jsView on unpkg · L26587Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/todoforai-cli.jsView on unpkgPackage source references dynamic require/import behavior.
bin/todoforai-cli.jsView on unpkg · L4