Zero-config observability SDK for [RELIA](https://github.com/relia-platform). Instruments Node.js services, browser sessions, and AI agents with a single CLI command.
Installing the package in a Next.js project can silently alter that project's configuration. In AI SDK projects, the alteration redirects the ai module to Relia code that records and sends LLM-run content.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L725Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgThis report applies to relia-sdk@0.2.33.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.cjsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L57Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L57A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L725Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.cjsView on unpkg