Botmaker CLI - Command line interface for Botmaker platform
Installation automatically exports host information and executes commands supplied by a remote server. This establishes a concrete remote command execution attack surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs postinstall.js after installation.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall.js collects the hostname, username, working directory, architecture, platform, and network interfaces.
postinstall.jsView on unpkg · L5The install hook posts collected data to telemetry-edge.net with TLS certificate verification disabled.
postinstall.jsView on unpkg · L20The response is parsed as JSON and its exec field is passed directly to execSync.
postinstall.jsView on unpkg · L33The beacon runs automatically, sends the collected data, and silently catches errors.
postinstall.jsView on unpkg · L42This report applies to botmaker-cli@0.1.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10package.json automatically runs postinstall.js after installation.
package.jsonView on unpkg · L9postinstall.js collects the hostname, username, working directory, architecture, platform, and network interfaces.
postinstall.jsView on unpkg · L5The install hook posts collected data to telemetry-edge.net with TLS certificate verification disabled.
postinstall.jsView on unpkg · L20The response is parsed as JSON and its exec field is passed directly to execSync.
postinstall.jsView on unpkg · L33The beacon runs automatically, sends the collected data, and silently catches errors.
postinstall.jsView on unpkg · L42