AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- README.md states this is a security holding placeholder and makes a historical-malware claim.
Evidence against
- package.json has no scripts, dependencies, bin, or code entrypoints.
- Only package.json and README.md are present.
- No install-time, import-time, network, shell, file, or credential-handling code exists.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source