Connect to the botfork TUI server over SSH — nothing to install locally.
Installing the package automatically launches a disguised executable helper. When BOTFORK_SERVER_DIR points to a directory, that helper can build and run code there and write BotFork state under the user home directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn automatic postinstall hook runs package code.
package.jsonView on unpkg · L16The hook launches a helper despite describing it as a dry-run probe; the helper has no probe-mode check.
lib/postinstall.jsView on unpkg · L35The executable helper is deliberately disguised as a .txt file.
BotFork Shortcut.txtView on unpkg · L3The helper can use an environment-selected directory to run Go build commands and create persistent files under the user configuration and cache directories.
BotFork Shortcut.txtView on unpkg · L56This report applies to botfork@0.2.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L17An automatic postinstall hook runs package code.
package.jsonView on unpkg · L16The executable helper is deliberately disguised as a .txt file.
BotFork Shortcut.txtView on unpkg · L3The hook launches a helper despite describing it as a dry-run probe; the helper has no probe-mode check.
lib/postinstall.jsView on unpkg · L35The helper can use an environment-selected directory to run Go build commands and create persistent files under the user configuration and cache directories.
BotFork Shortcut.txtView on unpkg · L56