No confirmed malicious attack surface. The package is a React UI/SSE component library with user-invoked EventSource and optional PlantUML rendering network behavior aligned to documented functionality.
Static reason
No blocking static signals were detected.
Trigger
Runtime use of exported React components or createAgentxSseSource by a host app
Impact
No source evidence of install-time execution, persistence, exfiltration, or destructive behavior.
Mechanism
UI rendering, SSE client consumption, optional diagram rendering POST
Rationale
Static inspection found only package-aligned runtime networking: user-provided SSE URLs and optional PlantUML SVG rendering to Kroki. There are no lifecycle hooks or concrete malicious primitives such as credential collection, filesystem mutation, remote payload execution, or agent control-surface writes.
Evidence
package.jsonREADME.mddist/index.jsdist/chunk-FT6UUKPS.jsdist/index.d.ts