Read-only Linux sandbox boundary assessment with privileged lifecycle visibility
Installing the package automatically executes a host and sandbox reconnaissance script. Results are stored under /tmp and echoed through npm install output. No network exfiltration or agent-config write was found.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall runs node scripts/assess.js on every npm install, before any user command.
package.jsonView on unpkg · L9assess.js uses child_process.execSync to collect identity, processes, mounts, routes, listeners, SUID files, capabilities, and writable directories.
scripts/assess.jsView on unpkg · L8It stats container runtime sockets and device nodes such as docker.sock, containerd.sock, and /dev/mem, then writes report.json and SUMMARY.txt under /tmp and prints check output to the install log.
scripts/assess.jsView on unpkg · L36It stats container runtime sockets and device nodes such as docker.sock, containerd.sock, and /dev/mem, then writes report.json and SUMMARY.txt under /tmp and prints check output to the install log.
scripts/assess.jsView on unpkg · L64Environment variable names are recorded while values are redacted; the bin entry only tells the user the assessment already ran at install.
scripts/assess.jsView on unpkg · L50Environment variable names are recorded while values are redacted; the bin entry only tells the user the assessment already ran at install.
bin/sandbox-pentest.jsView on unpkg · L2This report applies to sandbox-pentest-assessment@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L10preinstall runs node scripts/assess.js on every npm install, before any user command.
package.jsonView on unpkg · L9Environment variable names are recorded while values are redacted; the bin entry only tells the user the assessment already ran at install.
bin/sandbox-pentest.jsView on unpkg · L2assess.js uses child_process.execSync to collect identity, processes, mounts, routes, listeners, SUID files, capabilities, and writable directories.
scripts/assess.jsView on unpkg · L8It stats container runtime sockets and device nodes such as docker.sock, containerd.sock, and /dev/mem, then writes report.json and SUMMARY.txt under /tmp and prints check output to the install log.
scripts/assess.jsView on unpkg · L36Environment variable names are recorded while values are redacted; the bin entry only tells the user the assessment already ran at install.
scripts/assess.jsView on unpkg · L50It stats container runtime sockets and device nodes such as docker.sock, containerd.sock, and /dev/mem, then writes report.json and SUMMARY.txt under /tmp and prints check output to the install log.
scripts/assess.jsView on unpkg · L64