FRAIM: AI Workforce Infrastructure — the organizational capability that turns AI agents into an accountable workforce, their operators into capable AI managers, and executives into leaders with clear optics on AI proficiency.
Static analysis flagged 17 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/src/core/utils/git-utils.jsView on unpkg · L9Package source references dynamic require/import behavior.
bin/fraim.jsView on unpkg · L10Source writes installer persistence such as shell profile or service configuration.
dist/src/ai-hub/word-sideload.jsView on unpkg · L21A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/cli/doctor/checks/mcp-connectivity-checks.jsView on unpkg · L53Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cli/commands/override.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
dist/src/cli/setup/user-level-sync.jsView on unpkg · L95This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/src/cli/commands/add-provider.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L46Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L46This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/src/cli/commands/add-provider.jsView on unpkgPackage source references child process execution.
dist/src/core/utils/git-utils.jsView on unpkg · L9Package source references dynamic require/import behavior.
bin/fraim.jsView on unpkg · L10Source writes installer persistence such as shell profile or service configuration.
dist/src/ai-hub/word-sideload.jsView on unpkg · L21A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/cli/doctor/checks/mcp-connectivity-checks.jsView on unpkg · L53Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cli/commands/override.jsView on unpkg · L10Package source invokes a package manager install command at runtime.
dist/src/cli/setup/user-level-sync.jsView on unpkg · L95