Loading npm security reports…
See where your coding agents' tokens and dollars actually go.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
dist/statusline-ES3W3TEU.js writes ~/.claude/settings.json when the user explicitly runs `tokz statusline enable`.
dist/statusline-ES3W3TEU.jsView on unpkgdist/statusline-ES3W3TEU.js writes ~/.claude/settings.json when the user explicitly runs `tokz statusline enable`.
dist/statusline-ES3W3TEU.jsView on unpkg