Loading npm security reports…
AI 外呼 CLI
User-invoked CLI execution reaches obfuscated runtime code. It persists user-supplied calling credentials and makes outbound API calls. Shell command construction leaves a command-injection risk if supplied or CRM-derived fields are attacker-controlled.
Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1Package source references dynamic require/import behavior.
bin/aicall.jsView on unpkg · L18Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/bundle.cjsView on unpkg · L1