Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@e-llm-studio/[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@e-llm-studio/[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Large Javascript Payload: 5325260 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 70 · status changed
Evidence
Static findings
21 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index.mjs | 5325260 bytes | 10 |
Show all 21 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index.mjs | 5325260 bytes | 10 |
| low | Obfuscation | package/dist/cjs/features/DocumentLearning/_components/ChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/InstantLearning/_components/ChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/DocumentLearning/_components/ChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/InstantLearning/_components/ChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/InstantLearning/_components/ConflictingLearningWarnCardDB.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/InstantLearning/_components/ConflictingLearningWarnCardDB.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/InstantLearning/_components/ContextualChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/InstantLearning/_components/ContextualChatComponent.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/InstantLearning/_components/ContextualConflictDBCard.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/InstantLearning/_components/ContextualConflictDBCard.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/InstantLearning/_components/LearningDetailsForm.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/InstantLearning/_components/LearningDetailsForm.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/IL-OTJ/_components/MessageRendering/MessageRendering.js | matched "\\u00A0" | 3 |
| low | Obfuscation | package/dist/features/IL-OTJ/_components/MessageRendering/MessageRendering.js | matched "\\u00A0" | 3 |
| low | Obfuscation | package/dist/cjs/features/WtaWnta/_components/SimilarConflictingCard.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/WtaWnta/_components/SimilarConflictingCard.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/cjs/features/IL-OTJ/helpers/utils.js | matched "\\u00A0" | 3 |
| low | Obfuscation | package/dist/features/IL-OTJ/helpers/utils.js | matched "\\u00A0" | 3 |
| low | Obfuscation | package/dist/cjs/features/WtaWnta/_components/ValidationCard.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/features/WtaWnta/_components/ValidationCard.js | matched "fromCharCode" | 3 |
Manifest
Package metadata
Scripts7
buildrollup -c && node scripts/fix-casing.mjsejectcraco ejectformat:changednpx lint-stagedpostbuildnode scripts/fix-casing.mjsstartcraco starttestcraco testtsupBuildtsup src/index.ts
Dependencies22
@craco/craco^7.1.0@e-llm-studio/citation^0.0.165@e-llm-studio/watch-me-work^0.0.25@radix-ui/react-tooltip^1.2.8@react-pdf-viewer/core^3.12.0@react-pdf-viewer/page-navigation^3.12.0@react-pdf-viewer/search^3.12.0@react-pdf-viewer/zoom^3.12.0@viswa-test/test-citation^0.0.109date-fns^4.1.0framer-motion^12.38.0pdf-collaborative-tool^0.7.0pdfjs-dist^3.11.174primeicons^7.0.0primereact^10.9.7react>=16.8.0 <19.0.0react-dom>=16.8.0 <19.0.0react-hot-toast^2.6.0react-konva^17.0.2-6react-player^3.4.0wavesurfer.js^7.12.5zustand^5.0.13