Developer Environment Manager
A user can configure an arbitrary API base URL, then a credentialed scan sends the saved IOBend token and repository scan metadata to that destination. This is conditional credential exposure, not install-time activity.
Source writes installer persistence such as shell profile or service configuration.
src/commands/dotfiles/index.jsView on unpkg · L5Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/commands/verify/index.jsView on unpkg · L10Source appears to send environment or credential material to an external endpoint.
src/commands/scan/index.jsView on unpkg · L4A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/commands/scan/index.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/commands/info/index.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion/index.jsView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/deps/index.jsView on unpkgThis report applies to iobend@2.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/commands/dotfiles/index.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/deps/index.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/commands/verify/index.jsView on unpkg · L10Source appears to send environment or credential material to an external endpoint.
src/commands/scan/index.jsView on unpkg · L4A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/commands/scan/index.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/commands/info/index.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion/index.jsView on unpkg · L10