AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- README.md states this is a security holding package for previously removed malicious code.
Evidence against
- package.json contains only name, version, description, and repository metadata.
- package.json defines no lifecycle scripts or executable entrypoints.
- Package contains only package.json and README.md; no source, binaries, or payload files.
- No network, credential, filesystem-write, shell, dynamic-loading, or AI-agent-control code is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source