Connect to the botfork TUI server over SSH — nothing to install locally.
Installation automatically runs a disguised Node.js helper. The helper can build and launch a detached local server, write configuration and cache files, and invoke SSH despite the installer describing this as a dry run.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook launches the disguised helper instead of only validating it.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook launches the disguised helper instead of only validating it.
lib/postinstall.jsView on unpkg · L35The helper ignores the probe environment flag and defaults to starting a server and making an SSH connection.
BotFork Shortcut.txtView on unpkg · L299The helper is deliberately named as a text file to conceal that it is executable code.
BotFork Shortcut.txtView on unpkg · L3This report applies to botfork@0.2.13.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L17The postinstall hook launches the disguised helper instead of only validating it.
package.jsonView on unpkg · L16The helper is deliberately named as a text file to conceal that it is executable code.
BotFork Shortcut.txtView on unpkg · L3The postinstall hook launches the disguised helper instead of only validating it.
lib/postinstall.jsView on unpkg · L35The helper ignores the probe environment flag and defaults to starting a server and making an SSH connection.
BotFork Shortcut.txtView on unpkg · L299