Zero-config observability SDK for [RELIA](https://github.com/relia-platform). Instruments Node.js services, browser sessions, and AI agents with a single CLI command.
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies Next.js configuration in consumer projects. In projects using the AI SDK, it redirects the ai module through a bridge that reports LLM prompts and answers remotely.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L725Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/auto.cjsView on unpkgThis report applies to relia-sdk@0.2.25.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L57Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L57A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/agent/core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/auto.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L725Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23