FRAIM core CLI and MCP package.
Static analysis flagged 18 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references child process execution.
dist/src/core/utils/git-utils.jsView on unpkg · L9Package source references dynamic require/import behavior.
bin/fraim.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/src/first-run/session-service.jsView on unpkg · L44Source writes installer persistence such as shell profile or service configuration.
dist/src/first-run/session-service.jsView on unpkg · L44Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cli/doctor/checks/scripts-checks.jsView on unpkg · L14Package source invokes a package manager install command at runtime.
dist/src/cli/setup/user-level-sync.jsView on unpkg · L95Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/setup/user-level-sync.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/commands/override.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/setup/first-run.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/utils/remote-sync.jsView on unpkgPackage source references child process execution.
dist/src/core/utils/git-utils.jsView on unpkg · L9Package source references dynamic require/import behavior.
bin/fraim.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/commands/override.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/setup/first-run.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/utils/remote-sync.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/src/first-run/session-service.jsView on unpkg · L44Source writes installer persistence such as shell profile or service configuration.
dist/src/first-run/session-service.jsView on unpkg · L44Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cli/doctor/checks/scripts-checks.jsView on unpkg · L14Package source invokes a package manager install command at runtime.
dist/src/cli/setup/user-level-sync.jsView on unpkg · L95Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli/setup/user-level-sync.jsView on unpkg