AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- `README.md` states this is a security holding package replacing a removed malicious release.
Evidence against
- `package.json` has no lifecycle scripts, entrypoints, dependencies, or bin declarations.
- Package contains only `package.json` and `README.md`; no executable source or payload files.
- No network, filesystem-write, credential, shell, eval, or AI-agent-control behavior is present in the inspected files.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source