AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- `README.md` states this is a security holding package for a previously removed malicious release.
Evidence against
- `package.json` contains only package metadata; no lifecycle scripts or runtime entrypoints.
- Package root contains only `package.json` and `README.md`; no executable source, binaries, or dependencies.
- No network, filesystem-write, shell, eval, credential-harvesting, or agent-control code is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source