Run .m source files in the browser and on the command line by compiling to JavaScript
No confirmed malicious attack surface. The observed fetch, filesystem, and dynamic-execution primitives implement explicit CLI/compiler functionality.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist-lib/node.jsView on unpkg · L305A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist-lib/node.jsView on unpkg · L305Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist-browser/browser.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
dist-cli/cli.jsView on unpkg · L16This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-cli/cli.jsView on unpkgPackage ships WebAssembly modules.
dist-site-viewer/assets/qhull-DM50poqF.wasmView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist-site-viewer/assets/hdf5_hl-C9YUKPMe.jsView on unpkgThis report applies to numbl@0.4.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist-cli/cli.jsView on unpkg · L16A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-cli/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L71Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L71Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist-browser/browser.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
dist-cli/cli.jsView on unpkg · L16This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist-cli/cli.jsView on unpkgPackage ships WebAssembly modules.
dist-site-viewer/assets/qhull-DM50poqF.wasmView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist-site-viewer/assets/hdf5_hl-C9YUKPMe.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist-lib/node.jsView on unpkg · L305A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist-lib/node.jsView on unpkg · L305Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist-cli/cli.jsView on unpkg · L16A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-cli/cli.jsView on unpkg