Agent-first terminal workspace for Nolo
LPM flags this version as an AI-agent control-surface risk. The connector injects reviewer and release-control instructions into an AI agent prompt. A prompted agent can be directed to continue review and release workflows, including background execution.
Package source references dynamic require/import behavior.
chunk-72COHDZR.jsView on unpkg · L11832Package source references a known benign dynamic code generation pattern.
chunk-72COHDZR.jsView on unpkg · L18567Package source references child process execution.
machineCommands-JZVC7JEX.jsView on unpkg · L148Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
machineCommands-JZVC7JEX.jsView on unpkg · L6This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
chunk-T5HJEUQN.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-T5HJEUQN.jsPackage source references weak cryptographic algorithms.
chunk-S3HB4CQY.jsView on unpkg · L160A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chunk-HMMOAG2I.js#virtual:normalized:round1View on unpkgThis report applies to nolo-cli@0.52.0-alpha.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
chunk-72COHDZR.jsView on unpkg · L11832Package source references a known benign dynamic code generation pattern.
chunk-72COHDZR.jsView on unpkg · L18567A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chunk-HMMOAG2I.js#virtual:normalized:round1View on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
Package source references child process execution.
machineCommands-JZVC7JEX.jsView on unpkg · L148Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-T5HJEUQN.jsView on unpkg · L23This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
chunk-T5HJEUQN.jsView on unpkgPackage source references weak cryptographic algorithms.
chunk-S3HB4CQY.jsView on unpkg · L160