First Tree — unified CLI for Context Tree onboarding, agent management, and team messaging. (Source-tree dev build; CI rewrites `name` and `bin` for prod / staging publishes — see docs/local-dev-isolation.md.)
No confirmed malicious attack surface. The install hook only prunes named bundled dependencies in global installs, while runtime networking serves the package's configured First Tree service and sanitized error telemetry.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/connect-token-BAkX646G.mjsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Source executes local commands and sends command output to an external endpoint.
dist/connect-token-BAkX646G.mjsView on unpkg · L18A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Package source references child process execution.
dist/connect-token-BAkX646G.mjsView on unpkg · L22Package source references shell execution.
dist/connect-token-BAkX646G.mjsView on unpkg · L20867A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Package source invokes a package manager install command at runtime.
dist/connect-token-BAkX646G.mjsView on unpkg · L95022A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/connect-token-BAkX646G.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/connect-token-BAkX646G.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L49Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L49Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/connect-token-BAkX646G.mjsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Source executes local commands and sends command output to an external endpoint.
dist/connect-token-BAkX646G.mjsView on unpkg · L18A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Package source references child process execution.
dist/connect-token-BAkX646G.mjsView on unpkg · L22Package source references shell execution.
dist/connect-token-BAkX646G.mjsView on unpkg · L20867A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/connect-token-BAkX646G.mjsView on unpkg · L18Package source invokes a package manager install command at runtime.
dist/connect-token-BAkX646G.mjsView on unpkg · L95022A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/connect-token-BAkX646G.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/connect-token-BAkX646G.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/connect-token-BAkX646G.mjsView on unpkg · L18