Agent-first terminal workspace for Nolo
No concrete attack was established in the inspected source. Final clean clearance requires citation coverage that exceeds this response's permitted citation count.
Package source references shell execution.
chunk-2SYTUTLI.js#virtual:normalized:round1View on unpkg · L53Package source references a known benign dynamic code generation pattern.
chunk-GA77XY7N.jsView on unpkg · L8386Package source references dynamic require/import behavior.
pdf-U6KSUEZZ.jsView on unpkg · L9159Package source references weak cryptographic algorithms.
chunk-QZYL5UNG.jsView on unpkg · L193Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
chunk-YUNJN43V.jsView on unpkg · L30Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
chunk-PHINMJJZ.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-2SYTUTLI.jsView on unpkg · L23Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
machineCommands-HLEUUEKS.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chromeCommands-K27J4OVZ.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-NJC2W7I4.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
chunk-MP64VFGD.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
chunk-M5PVFLD4.jsView on unpkgThis report applies to nolo-cli@0.92.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references shell execution.
chunk-2SYTUTLI.js#virtual:normalized:round1View on unpkg · L53Package source references a known benign dynamic code generation pattern.
chunk-GA77XY7N.jsView on unpkg · L8386Package source references dynamic require/import behavior.
pdf-U6KSUEZZ.jsView on unpkg · L9159Package source references weak cryptographic algorithms.
chunk-QZYL5UNG.jsView on unpkg · L193Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
chunk-PHINMJJZ.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
machineCommands-HLEUUEKS.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
chromeCommands-K27J4OVZ.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-NJC2W7I4.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
chunk-MP64VFGD.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
chunk-M5PVFLD4.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
chunk-YUNJN43V.jsView on unpkg · L30Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
chunk-2SYTUTLI.jsView on unpkg · L23