AI-native pluggable CLI framework
Installing the package automatically downloads and writes skills into broad AI-agent client directories. It also removes legacy agent skills and a home-directory state directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3This report applies to @yunkeai/yunke-cli@2.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkg