AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- README.md states this is a security holding package and references previously removed malicious code.
Evidence against
- package.json contains only metadata; no scripts, dependencies, or entrypoints.
- Package contains only package.json and README.md.
- No executable source, install hook, network client, or file-writing logic is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source