No confirmed malicious attack surface. Runtime networking is component-aligned: caller-configured SSE and optional PlantUML rendering.
Static reason
No blocking static signals were detected.
Trigger
A consuming application renders the UI and supplies an SSE URL or renders PlantUML content.
Impact
Sends supplied stream or diagram content to application-selected endpoints; no install-time or hidden execution found.
Mechanism
Browser-side SSE consumption and optional PlantUML SVG rendering.
Rationale
Source inspection shows a React UI library whose network calls are explicit display features. The only fixed remote host is the documented optional PlantUML renderer, and no malicious execution or data-harvesting chain is present.
Evidence
package.jsondist/index.jsdist/chunk-32H5OCBB.jsREADME.md