火山方舟 ARK 平台命令行工具
Installing the package automatically downloads and executes an opaque native binary. That binary is invoked to refresh and install skills into automatically detected agents.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs the installer.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgThe installer downloads a platform binary, verifies it, and writes it into the package.
scripts/postinstall.jsView on unpkg · L168This report applies to @volcengine/ark-cli@1.0.26.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L14An automatic postinstall hook runs the installer.
package.jsonView on unpkg · L13The installer downloads a platform binary, verifies it, and writes it into the package.
scripts/postinstall.jsView on unpkg · L168Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg