AI called this Clean at 98.0% confidence as Benign with low false-positive risk.
Evidence against
- package.json has no scripts, dependencies, bin, main, module, browser, or exports entrypoints.
- Only package files present are package.json and README.md.
- Manifest describes a security holding package with repository npm/security-holder.
- No source files, lifecycle hooks, network endpoints, credential access, shell execution, eval, native loading, persistence, or AI-agent config writes found.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source