Tokenade — cut your AI coding agent's token bill. Installs the Tokenade CLI (a local, paid token-reduction tool; activate via your browser).
The fallback installer executes remotely supplied native code during installation and removes macOS quarantine. This creates an unresolved execution risk, but inspected source does not establish an active malicious attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install.jsView on unpkg · L25Install-named source file stages remote content through filesystem writes and execution.
install.jsView on unpkg · L25A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/tokenade.js#virtual:normalized:round1View on unpkgThis report applies to @tokenade/cli@1.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L13A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/tokenade.js#virtual:normalized:round1View on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
install.jsView on unpkg · L25Install-named source file stages remote content through filesystem writes and execution.
install.jsView on unpkg · L25Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg