Agent-first terminal workspace for Nolo
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references dynamic require/import behavior.
chunk-TR4DXUYX.jsView on unpkg · L11902Package source references a known benign dynamic code generation pattern.
chunk-TR4DXUYX.jsView on unpkg · L19993Package source references child process execution.
readlineWorkspace-XUFJV3RS.jsView on unpkg · L3730Package source references weak cryptographic algorithms.
chunk-EJE33XNR.jsView on unpkg · L170This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
chunk-T5HJEUQN.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-T5HJEUQN.jsView on unpkg · L23Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
machineCommands-RK6L7ZWL.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chunk-BY2FF2C4.js#virtual:normalized:round1View on unpkgThis report applies to nolo-cli@0.54.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
chunk-TR4DXUYX.jsView on unpkg · L11902Package source references a known benign dynamic code generation pattern.
chunk-TR4DXUYX.jsView on unpkg · L19993Package source references weak cryptographic algorithms.
chunk-EJE33XNR.jsView on unpkg · L170A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chunk-BY2FF2C4.js#virtual:normalized:round1View on unpkgPackage source references child process execution.
readlineWorkspace-XUFJV3RS.jsView on unpkg · L3730Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-T5HJEUQN.jsView on unpkg · L23This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
chunk-T5HJEUQN.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.