AI-native pluggable CLI framework
Installing the package automatically deletes legacy agent-related files and downloads skills into detected AI-agent directories. The installation does not require a separate user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bundle.jsView on unpkgPackage source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L10Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2This report applies to @yunkeai/yunke-cli@2.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L10A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bundle.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkg