TensorLake SDK for applications, sandboxes, and cloud services
No confirmed malicious attack surface was established. Network and subprocess capabilities are SDK and explicitly invoked CLI features, not install-time behavior.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package source references dynamic require/import behavior.
bin/tensorlake-deploy.cjsView on unpkg · L2This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/applications/index.cjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/applications/index.cjsView on unpkg · L52No install lifecycle hook is declared in the manifest.
package.jsonView on unpkg · L46This report applies to tensorlake@0.5.128.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
bin/tensorlake-deploy.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/applications/index.cjsView on unpkg · L52This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/applications/index.cjsView on unpkgNo install lifecycle hook is declared in the manifest.
package.jsonView on unpkg · L46