Loading npm security reports…
**English** | [简体中文](README.cn.md)
Static analysis completed at 65.0% confidence. No malicious behavior was detected; 10 low-signal pattern(s) were surfaced and cleared.
Package source references dynamic require/import behavior.
scripts/copy-flag-assets.jsView on unpkg · L6Manifest entrypoint contains risky behavior absent from dist/build output.
scripts/scaffold-app.jsView on unpkg · L12Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-cursor-rules.jsView on unpkgPackage source references dynamic require/import behavior.
scripts/copy-flag-assets.jsView on unpkg · L6Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/install-cursor-rules.jsView on unpkgManifest entrypoint contains risky behavior absent from dist/build output.
scripts/scaffold-app.jsView on unpkg · L12