Loading npm security reports…
BYOK fork of the Codebuff CLI. Bring your own provider key (OpenAI, Anthropic, OpenRouter, OpenCode Zen/Go, custom OpenAI-compat). No codebuff.com account required.
Static analysis flagged 10 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to codebuff-mod@1.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11