<p align="center"> <img src="https://raw.githubusercontent.com/osolmaz/mlclaw/main/assets/mlclaw.svg" alt="ML Claw" width="180"> </p>
No confirmed malicious attack surface. Network, subprocess, and filesystem actions implement explicit deployment, runtime setup, and state synchronization workflows.
Package source references child process execution.
dist/hf-state-sync.jsView on unpkg · L4946Source executes local commands and sends command output to an external endpoint.
dist/mlclaw.mjsView on unpkg · L47A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/mlclaw.mjsView on unpkg · L47Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/mlclaw.mjsView on unpkg · L47Source combines credential-like environment material and outbound requests; review data flow before blocking.
assets/hf-tooling/skills/huggingface-tool-builder/references/baseline_hf_api.tsxView on unpkg · L39This report applies to mlclaw@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/hf-state-sync.jsView on unpkg · L4946Source executes local commands and sends command output to an external endpoint.
dist/mlclaw.mjsView on unpkg · L47A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/mlclaw.mjsView on unpkg · L47Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/mlclaw.mjsView on unpkg · L47Source combines credential-like environment material and outbound requests; review data flow before blocking.
assets/hf-tooling/skills/huggingface-tool-builder/references/baseline_hf_api.tsxView on unpkg · L39