@execbox/quickjs
QuickJS executor for the execbox core package across inline and worker hosts.
8
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
aallam
Keywords
mcpmodel-context-protocolquickjssandboxcode-execution
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@execbox/protocol | AI (dependencies): Sibling package in the same execbox monorepo; consistent versioning and shared publisher context. | ai | |
| provenance | no-provenance | AI (provenance): Absence of provenance is common (~88% of npm); no other risk signals present. | ai | |
| dependencies | unvetted-dep:@execbox/core | AI (dependencies): Sibling package from the same monorepo (github.com/aallam/execbox); expected internal dependency. | ai |