CLI for DesignKit Team Agent
No confirmed malicious attack surface was established. Launching the CLI executes an extensively obfuscated bundle before command parsing, leaving its effective behavior unresolved.
Package source references dynamic require/import behavior.
bin/designkit-cli.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L1This report applies to meitu-designkit-cli@1.0.63.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
bin/designkit-cli.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L1