Loading npm security reports…
Importing the SDK runs a concealed third-party provider loader outside the documented marketplace API. The package does not show the loaded dependency's behavior, so the payload risk is unresolved but real.
Importing the client invokes initializeProvider automatically.
dist/client.jsView on unpkg · L167Package source references dynamic require/import behavior.
dist/client.jsView on unpkg · L172Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/client.jsView on unpkg · L172Importing the client invokes initializeProvider automatically.
dist/client.jsView on unpkg · L167Package declares a runtime dependency whose name matches a Node built-in module.
package.jsonView on unpkg · L24