Remote worker agent for Yeaft Web Code Agent — connects the native Yeaft engine, CLI providers, and workbench tools
Static analysis completed at 93.0% confidence. No malicious behavior was detected; 23 low-signal pattern(s) were surfaced and cleared.
Package source references child process execution.
windows-upgrade-runner.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
connection/upgrade.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
local-runtime/web/jszip.min.jsView on unpkg · L12Package source references dynamic require/import behavior.
local-runtime/web/docx-preview.min.jsView on unpkg · L1Package source executes code through a VM context API.
yeaft/tools/js-repl.jsView on unpkg · L1Package source references weak cryptographic algorithms.
local-runtime/server/browser-runtime-routes.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
local-run.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
service/macos.jsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
browser-runtime/windows-version-job.ps1View on unpkgPackage ships high-entropy non-source blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgPackage ships compressed or archive-like blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
local-runtime/web/mermaid.min.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkgPackage source references child process execution.
windows-upgrade-runner.jsView on unpkg · L1Package source executes code through a VM context API.
yeaft/tools/js-repl.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches persistence behavior.
service/macos.jsView on unpkg · L3Package ships non-JavaScript build or shell helper files.
browser-runtime/windows-version-job.ps1View on unpkgPackage ships high-entropy non-source blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgPackage ships compressed or archive-like blobs.
local-runtime/web/xlsx.min.js.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
local-runtime/web/mermaid.min.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
connection/upgrade.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
local-runtime/web/jszip.min.jsView on unpkg · L12Package source references dynamic require/import behavior.
local-runtime/web/docx-preview.min.jsView on unpkg · L1Package source references weak cryptographic algorithms.
local-runtime/server/browser-runtime-routes.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
local-run.jsView on unpkg · L1