Developer Environment Manager
An authenticated marketplace install can write server-provided content to a server-provided resolved path. The path is not constrained to the project or an extension directory.
Source writes installer persistence such as shell profile or service configuration.
src/commands/dotfiles/index.jsView on unpkg · L5Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/commands/verify/index.jsView on unpkg · L10Source appears to send environment or credential material to an external endpoint.
src/commands/scan/index.jsView on unpkg · L4A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/commands/scan/index.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/commands/info/index.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion/index.jsView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/deps/index.jsView on unpkgThis report applies to iobend@2.6.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/commands/dotfiles/index.jsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/commands/deps/index.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/commands/verify/index.jsView on unpkg · L10Source appears to send environment or credential material to an external endpoint.
src/commands/scan/index.jsView on unpkg · L4A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/commands/scan/index.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/commands/info/index.jsView on unpkg · L11A manifest entrypoint or package-local install chain reaches persistence behavior.
src/commands/completion/index.jsView on unpkg · L10