AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence against
- `package.json` has no lifecycle scripts or executable entrypoints.
- Only `package.json` and `README.md` are present.
- No code, network endpoint, credential access, shell execution, or agent-control writes found.
- `README.md` describes this release as a security holding placeholder.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source