All @agent-facets/cli-linux-x64-baseline versions
@agent-facets/cli-linux-x64-baseline @0.7.3
Maintainers
Risk Dispositions (1 applicable to this version, 1 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
bogus-package |
bogus-package | reject | AI | AI (bogus-package): Known spam maintainer (jimador) added; package is a near-empty payload with no legitimate ecosystem signals. |
Show 1 disposition(s) that do not match any finding on this version
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
maintainer-added |
maintainer-change | reject | AI | AI (maintainer-change): New maintainer jimador is a known spam publisher; generalizes across versions of this package. |
SAST Findings (2)
[Always reject] Matched 5 signal(s), weighted score 5: • [S_DESC_MATCHES_NAME] Description is empty or just restates the package name. • [S_NO_REPO_NO_HOME] No repository, homepage, or bugs URL — genuine packages almost always link somewhere. • [S_NO_KEYWORDS] No keywords declared. • [S_NO_DEPS] No runtime, dev, peer, or optional dependencies declared. • [S_TINY_PAYLOAD] Tiny payload: 0 code file(s), 128 bytes total.
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Review Summary
Risk score: 40. Findings: 1 critical (+40), 3 info (+0).
Published to npm: