AI-native pluggable CLI framework
LPM flags this version as an AI-agent control-surface risk. Installation automatically distributes remote skills into broad AI-agent skill directories. No user command or per-client consent gate is required.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundle.jsView on unpkgPackage source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L11Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3This report applies to @yunkeai/yunke-cli@2.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundle.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundle.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/bundle.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundle.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundle.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.cjsView on unpkg · L3Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
scripts/postinstall.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkg