CLI for isolated Docker environments for microservice testing
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically mutates global AI-agent configuration and instruction files. It registers a command that AI tools can invoke as an MCP server.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
shared/config/dist/index.jsView on unpkg · L16Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
apps/cli/dist/lib/llm-context-register.jsView on unpkg · L30A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
apps/cli/dist/lib/inspect-step-detail.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/service-manager/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/lib/registry-credentials.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/platform/dist/platform-unix.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/service-manager/dist/environment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/telemetry/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/baselines-ops.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/baselines.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/dump.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/dump.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/run-helpers.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/lib/editor.jsView on unpkgThis report applies to dokkimi@0.5.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L41A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
apps/cli/dist/lib/inspect-step-detail.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/service-manager/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/lib/registry-credentials.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/platform/dist/platform-unix.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/service-manager/dist/environment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
shared/telemetry/dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/baselines-ops.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/baselines.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/dump.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/dump.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/commands/run-helpers.spec.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
apps/cli/dist/lib/editor.jsView on unpkgPackage source references dynamic require/import behavior.
shared/config/dist/index.jsView on unpkg · L16Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
apps/cli/dist/lib/llm-context-register.jsView on unpkg · L30