Halyard — an agent harness wired to Token Harbor. Built on DeepSeek Harness.
No confirmed malicious attack surface. The postinstall hook only rebrands installed harness display assets, while networked credential use is part of the user-invoked Token Harbor client flow.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
bin/halyard.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/halyard.mjsView on unpkg · L7This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/halyard.mjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/halyard.mjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/halyard.mjsView on unpkg · L7Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L30Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L30Source appears to send environment or credential material to an external endpoint.
bin/halyard.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/halyard.mjsView on unpkg · L7Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/halyard.mjsView on unpkg · L7A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/halyard.mjsView on unpkg · L7This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/halyard.mjsView on unpkg