Route/action layer for AI agents: one call (unbrowse "task" --url) reuses first-party site routes instead of browser loops. In-process CLI + Agent Skill + SDK. Bee aliases: @unbrowse/pollen-cli.
No confirmed attack surface was identified. The install hook performs package-local setup, and telemetry execution requires an explicit environment setting.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist-sdk/values/memzero.jsView on unpkg · L24Package ships native binary artifacts.
vendor/contract/linux-arm64/libcontract.soView on unpkgPackage ships non-JavaScript build or shell helper files.
runtime/curl-impersonate-fetch.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
runtime/mcp.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
runtime/mcp.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/unbrowse.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-sdk/runtime/paths.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/unbrowse-update-hint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgThis report applies to unbrowse@11.7.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L61Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L61Package ships native binary artifacts.
vendor/contract/linux-arm64/libcontract.soView on unpkgPackage ships non-JavaScript build or shell helper files.
runtime/curl-impersonate-fetch.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
runtime/mcp.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
runtime/mcp.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/unbrowse.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-sdk/runtime/paths.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/unbrowse-update-hint.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgPackage source references dynamic require/import behavior.
dist-sdk/values/memzero.jsView on unpkg · L24