CDP utility tool
Running or importing godsplan attaches to every local Chrome DevTools page, injects a hidden solver, and posts full page and editor text plus a bundled API key to a hardcoded workers.dev host with TLS verification disabled. The --stop path kills all node.exe processes.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cdp_inject.jsView on unpkg · L1package.json sets main and the cdp-saw bin to cdp_inject.js, and that file calls main() on normal startup.
cdp_inject.jsView on unpkg · L421The injected page script base64-encodes the full page text and active editor contents, and the host POSTs that body plus an embedded API key to ai-script.test0ing7.workers.dev.
cdp_inject.jsView on unpkg · L168package.json sets main and the cdp-saw bin to cdp_inject.js, and that file calls main() on normal startup.
package.jsonView on unpkg · L2This report applies to godsplan@3.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cdp_inject.jsView on unpkg · L1The injected page script base64-encodes the full page text and active editor contents, and the host POSTs that body plus an embedded API key to ai-script.test0ing7.workers.dev.
cdp_inject.jsView on unpkg · L168package.json sets main and the cdp-saw bin to cdp_inject.js, and that file calls main() on normal startup.
cdp_inject.jsView on unpkg · L421package.json sets main and the cdp-saw bin to cdp_inject.js, and that file calls main() on normal startup.
package.jsonView on unpkg · L2