Loading npm security reports…
Vantaloom local runtime for darwin-arm64.
Static analysis flagged 13 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references dynamic require/import behavior.
web/_next/static/chunks/a97a5cda6e9df469.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
cli/src/lib/lifecycle.mjsView on unpkg · L6Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
web/_next/static/chunks/a9f7b0c6041521a4.jsView on unpkg · L96Package source references dynamic require/import behavior.
web/_next/static/chunks/a97a5cda6e9df469.jsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
web/_next/static/chunks/a9f7b0c6041521a4.jsView on unpkg · L96Source writes installer persistence such as shell profile or service configuration.
cli/src/lib/lifecycle.mjsView on unpkg · L6