AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- `README.md` says this is a security holding package and claims prior malicious code was removed.
Evidence against
- `package.json` contains only package metadata; no scripts or executable entrypoints.
- The package contains only `package.json` and `README.md`; no source, binaries, or payload files.
- No lifecycle hooks, network endpoints, credential access, shell execution, dynamic loading, or agent-control writes were found.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source