Filesystem-first framework for durable backend AI agents that run anywhere.
No confirmed malicious install-time or import-time attack surface. Runtime OIDC support contacts Vercel only during authentication/token refresh.
Package source references dynamic require/import behavior.
bin/eve.jsView on unpkg · L8Package source references a known benign dynamic code generation pattern.
dist/src/compiled/gray-matter/index.jsView on unpkg · L43Package source executes code through a VM context API.
dist/src/compiled/@workflow/core/runtime.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/src/internal/authored-module-loader.jsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/internal/nitro/host/start-production-server.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
dist/src/compiled/_chunks/workflow/token-util-DNwIAn_u.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/compiled/@vercel/sandbox/index.jsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/src/compiled/_chunks/workflow/dist-eUxFublw.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/src/compiled/shadcn-registry/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/src/compiled/@photon-ai/chat-adapter-imessage/index.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Package source references dynamic require/import behavior.
bin/eve.jsView on unpkg · L8Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/compiled/@vercel/sandbox/index.jsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/src/compiled/_chunks/workflow/dist-eUxFublw.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
dist/src/compiled/shadcn-registry/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/src/compiled/@photon-ai/chat-adapter-imessage/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/src/compiled/gray-matter/index.jsView on unpkg · L43Package source executes code through a VM context API.
dist/src/compiled/@workflow/core/runtime.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/src/internal/authored-module-loader.jsView on unpkg · L3A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/internal/nitro/host/start-production-server.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
dist/src/compiled/_chunks/workflow/token-util-DNwIAn_u.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/src/compiled/_chunks/workflow/token-util-DNwIAn_u.jsView on unpkg · L1