CLI for Tonty Talents technical candidate evaluation — evaluate how engineers work with AI
Running the join command with a cloud session code downloads server-controlled metadata and executes its setup commands. It records keystrokes and terminal output from the launched AI tool, then uploads them to the relay.
Package source references child process execution.
dist/chunk-VHF6JTYK.jsView on unpkg · L105Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunk-VHF6JTYK.jsView on unpkg · L18Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-VHF6JTYK.jsView on unpkg · L18A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/chunk-VHF6JTYK.jsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty-darwin-x64/lib/unixTerminal.jsView on unpkgPackage source references dynamic require/import behavior.
vendor/node-pty-darwin-x64/lib/unixTerminal.jsView on unpkg · L31A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunk-VHF6JTYK.js#virtual:normalized:round1View on unpkg · L586A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-VHF6JTYK.js#virtual:normalized:round1View on unpkgPackage ships native binary artifacts.
vendor/node-pty-darwin-x64/build/Release/pty.nodeView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty-darwin-arm64/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/unixTerminal.jsView on unpkgThis report applies to tonty-tech-interviews@0.2.78.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunk-VHF6JTYK.jsView on unpkg · L18Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-VHF6JTYK.jsView on unpkg · L18A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/chunk-VHF6JTYK.jsView on unpkg · L18A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunk-VHF6JTYK.js#virtual:normalized:round1View on unpkg · L586A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunk-VHF6JTYK.js#virtual:normalized:round1View on unpkgPackage ships native binary artifacts.
vendor/node-pty-darwin-x64/build/Release/pty.nodeView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty-darwin-arm64/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/unixTerminal.jsView on unpkgPackage source references child process execution.
dist/chunk-VHF6JTYK.jsView on unpkg · L105Package source references dynamic require/import behavior.
vendor/node-pty-darwin-x64/lib/unixTerminal.jsView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty-darwin-x64/lib/unixTerminal.jsView on unpkg