The runtime module contains a dormant token-exfiltration path gated by an unconfigured webhook placeholder. No install-time execution or currently reachable third-party credential post exists in this release.
Source appears to send environment or credential material to an external endpoint.
Xerohub_Voice.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Xerohub_Voice.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
Xerohub_Voice.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
Xerohub_Voice.jsView on unpkg · L44Source appears to send environment or credential material to an external endpoint.
Xerohub_Voice.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Xerohub_Voice.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
Xerohub_Voice.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
Xerohub_Voice.jsView on unpkg · L44