Zero-config observability SDK for [RELIA](https://github.com/relia-platform). Instruments Node.js services, browser sessions, and AI agents with a single CLI command.
LPM flags this version as an AI-agent control-surface risk. Installation automatically modifies a consumer Next.js configuration, including an AI SDK alias. The resulting monitoring paths collect agent prompts, answers, and tool data and send reports to Relia endpoints.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L748Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/auto.cjsView on unpkgThis report applies to relia-sdk@0.2.42.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.cjsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L57Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L57A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/auto.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/auto.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/node.cjsView on unpkg · L6Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist/index.jsView on unpkg · L748Source appears to send environment or credential material to an external endpoint.
dist/cli.cjsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.cjsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.cjsView on unpkg · L23This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkg