Package evidence
@unieai/[email protected]
Oversized Unscanned: tarball exceeds the 50MB fetch cap; scanned registry metadata (install scripts + dependencies) only
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 12
- Versions published
- 5
- First published
- Apr 2026
- Publisher
- unieaidev
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@unieai/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@unieai/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Oversized Unscanned: tarball exceeds the 50MB fetch cap; scanned registry metadata (install scripts + dependencies) only
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Oversized Unscanned | manifest | tarball exceeds the 50MB fetch cap; scanned registry metadata (install scripts + dependencies) only | 0 |
Manifest
Package metadata
Scripts27
check:adapterscd adapters && bun testcheck:coveragebun run scripts/quality-gate/coverage.tscheck:desktopcd desktop && bun run lint && bun run test -- --run && bun run buildcheck:docsnpm ci --loglevel=error && npm run --loglevel=error docs:buildcheck:impactbun run scripts/pr/impact-report.tscheck:nativecd desktop && bun run build:sidecars && cd src-tauri && cargo checkcheck:persistence-upgradebun run scripts/quality-gate/persistence-upgrade.tscheck:policybun test scripts/pr/change-policy.test.ts scripts/pr/changed-files.test.ts scripts/pr/pr-triage-workflow.test.ts scripts/pr/pr-quality-workflow.test.ts scripts/pr/release-workflow.test.ts scripts/pr/quality-contract.test.ts scripts/git-hooks/install.test.ts scripts/quality-gate/quarantine.test.ts scripts/quality-gate/coverage.test.ts scripts/quality-gate/provider-smoke/execute.test.ts scripts/quality-gate/desktop-smoke/execute.test.ts scripts/quality-gate/providerTargets.test.ts scripts/quality-gate/runner.test.ts && bun run check:quarantinecheck:prbun run scripts/pr/check-pr.tscheck:quarantinebun run scripts/quality-gate/quarantine.ts --enforce-review-datecheck:serverbun run scripts/pr/run-server-tests.tsclaude-hahabun run ./bin/claude-hahadocs:buildvitepress build docsdocs:devvitepress dev docsdocs:previewvitepress preview docshooks:installbun run scripts/git-hooks/install.tsquality:baselinebun run quality:gate --mode baselinequality:gatebun run scripts/quality-gate/index.tsquality:prbun run quality:gate --mode prquality:providersbun run scripts/quality-gate/providers.tsquality:pushbun run quality:gate --mode pr --skip coveragequality:releasebun run quality:gate --mode releasequality:smokebun run quality:gate --mode baseline --allow-live --only 'provider-smoke:*' --only 'desktop-smoke:*'quality:verifybun run quality:prstartbun run ./bin/claude-hahaunieaibun run ./bin/claude-hahaverifybun run quality:pr
Dependencies64
@anthropic-ai/sandbox-runtime^0.0.44@anthropic-ai/sdk^0.80.0@aws-sdk/client-bedrock-runtime^3.1020.0@commander-js/extra-typings^14.0.0@growthbook/growthbook^1.6.5@modelcontextprotocol/sdk^1.29.0@opentelemetry/api-logs^0.214.0@opentelemetry/core^2.6.1@opentelemetry/resources^2.6.1@opentelemetry/sdk-logs^0.214.0@opentelemetry/sdk-metrics^2.6.1@opentelemetry/sdk-trace-base^2.6.1@opentelemetry/semantic-conventions^1.40.0ajv^8.18.0asciichart^1.5.25auto-bind^5.0.1axios^1.14.0bidi-js^1.0.3chalk^5.6.2chokidar^5.0.0cli-boxes^4.0.1code-excerpt^4.0.0diff^8.0.4emoji-regex^10.6.0env-paths^4.0.0execa^9.6.1figures^6.1.0fuse.js^7.1.0get-east-asian-width^1.5.0google-auth-library^10.6.2- …and 34 more.