@testmuai/kane-cli
KaneAI Terminal UI — browser automation testing agent
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/generate-headless-FYQ4IAPL.js | AI (source-diff): Bundler output (long lines from minification), sample shows normal API/CLI logic. | ai | |
| source-diff | obfuscated-file:dist/HelpView-DWUH3LLF.js | AI (source-diff): Bundled help-view component, standard CLI code. | ai | |
| source-diff | obfuscated-file:dist/HelpView-KHQYGSD2.js | AI (source-diff): esbuild-bundled help UI component, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-ODYT3HT7.js | AI (source-diff): esbuild-bundled app code, not obfuscation; large single-line bundle only. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-ZRRQT56R.js | AI (source-diff): Bundled build output (long minified lines), no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/HelpView-ZZYE2TKZ.js | AI (source-diff): Bundled CLI help-screen code, references legit project URLs. | ai | |
| source-diff | obfuscated-file:dist/HelpView-RIRNOKNM.js | AI (source-diff): Minified bundled CLI help view, legit repo URLs, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-J2Z5B3A5.js | AI (source-diff): Minified bundled build output, readable logic, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-VB52MM2A.js | AI (source-diff): esbuild bundle output for CLI feature, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/HelpView-35KKWQVE.js | AI (source-diff): Bundled help-view UI code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunk-BH6EP2LD.js | AI (source-diff): Bundled minified npm deps (minimatch etc.), not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-FX7EAINU.js | AI (source-diff): esbuild-bundled long lines, not true obfuscation; matches CLI's stated function. | ai | |
| source-diff | obfuscated-file:dist/HelpView-7SDQKJFW.js | AI (source-diff): Bundled help-screen component, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunk-Y6MB5JP7.js | AI (source-diff): Bundled minified dependency code, not a dropper; no malicious network/exec target. | ai | |
| source-diff | obfuscated-file:dist/HelpView-QPZCA6E3.js | AI (source-diff): Bundled help-view chunk; content is plain CLI text, no malicious behavior. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Declared dep used indirectly through bundled chunks. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Declared dep used indirectly through bundled chunks. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-2AVIJFUR.js | AI (source-diff): Bundled esbuild chunk with long minified lines, not true obfuscation; matches package's stated CLI functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-D3NAXZ2R.js | AI (source-diff): Bundled esbuild chunk with require polyfill + glob utils, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/HelpView-2T36LFLG.js | AI (source-diff): Minified bundle output containing help/UI text, benign. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-6SH67NQN.js | AI (source-diff): Minified bundle output, not true obfuscation; content is legit CLI logic. | ai | |
| dependencies | unvetted-dep:@testmuai/evidence-cli | AI (dependencies): Same-org sibling package from LambdaTest, not third-party. | ai | |
| source-diff | net-exec-file:dist/chunk-NFOBDHZK.js | AI (source-diff): Bundled evidence-cli schema/manifest code, no malicious behavior shown. | ai | |
| source-diff | net-exec-file:dist/chunk-2YQ6TW77.js | AI (source-diff): Bundled third-party lib code (minimatch-style), not obfuscation or a dropper. | ai | |
| source-diff | obfuscated-file:dist/HelpView-KBFE4EMP.js | AI (source-diff): Minified bundler output; sample shows a React/Ink help-view component, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-XWVVEFQR.js | AI (source-diff): Minified bundler output for a CLI tool; sample shows legitimate test-generation logic. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-WL6A6ACX.js | AI (source-diff): Minified CLI bundle; sampled code shows legitimate test-generation and TUI logic for LambdaTest KaneAI. | ai | |
| source-diff | obfuscated-file:dist/HelpView-HFKFRKG3.js | AI (source-diff): Minified CLI bundle; sampled code is a React/Ink help-view component referencing testmuai.com and LambdaTest GitHub. | ai | |
| source-diff | net-exec-file:dist/chunk-EEF6OT52.js | AI (source-diff): Minified Rollup/Vite bundle chunk; sampled code is standard glob/path library code, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/SummaryBox-FDNFQYSC.js | AI (source-diff): Standard esbuild/rollup bundle output; readable UI summary component, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/TestMdRunView-E4UDWIGT.js | AI (source-diff): Standard esbuild/rollup bundle output; readable React/Ink run view component, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/testmd-actions-O4NTH2OR.js | AI (source-diff): Standard esbuild/rollup bundle output; readable test action logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/run-test-md-5TNUTTEA.js | AI (source-diff): Standard esbuild/rollup bundle output; readable test-replay logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/HelpView-CDK7II5Q.js | AI (source-diff): Standard esbuild/rollup bundle output; readable React/Ink UI code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/HelpView-2IYG5AC3.js | AI (source-diff): Minified rollup/vite bundle output; content is HelpView UI component, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/chunk-6NEJEMA6.js | AI (source-diff): Bundled CLI chunk; network calls are the app's own API client, not a dropper. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/generate-headless-7UYAPXE5.js | AI (source-diff): Minified rollup/vite bundle output; content is application UI/API code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/run-test-md-3WLYVWFB.js | AI (source-diff): Minified ESM bundle for test-md replay; long lines are standard bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/HelpView-MXW6PGOP.js | AI (source-diff): Minified ESM bundle for CLI help view; long lines are standard bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-MBZOXXA4.js | AI (source-diff): Bundled CLI chunk; network calls and dynamic require are standard patterns in this tool's minified ESM output. | ai | |
| source-diff | net-exec-file:dist/chunk-VUIXILBR.js | AI (source-diff): Minified CLI bundle; network calls and dynamic require are part of normal CLI/browser-automation functionality, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/run-test-md-E2K4GEOB.js | AI (source-diff): Minified CLI bundle chunk; content is consistent with test-runner logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/HelpView-7LKN3TJT.js | AI (source-diff): Minified React/Ink UI component; long lines are standard bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-SOUKF5VL.js | AI (source-diff): Bundled CLI tool; network calls and dynamic require are standard in minified ESM bundles for this package. | ai | |
| source-diff | obfuscated-file:dist/HelpView-DOYUDPWZ.js | AI (source-diff): Minified React/Ink UI component; content is clearly legitimate CLI help view code. | ai | |
| source-diff | obfuscated-file:dist/HelpView-64BD2OKB.js | AI (source-diff): Minified React/Ink component referencing official LambdaTest repo URLs; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/HelpView-AZGTX7MR.js | AI (source-diff): Standard minified Vite/esbuild output for a React/Ink help view; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/chunk-6JF2T7BO.js | AI (source-diff): Bundled CLI dist chunk; network calls are legitimate API interactions, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/HelpView-ZR5EXR7F.js | AI (source-diff): Minified Vite/esbuild bundle; sample shows legitimate React/Ink UI code for the kane-cli help view. | ai | |
| source-diff | net-exec-file:dist/chunk-RFGE6ULZ.js | AI (source-diff): Bundled CLI output using createRequire for ESM/CJS interop; network calls are module imports, not exfiltration. | ai | |
| source-diff | obfuscated-file:dist/HelpView-2ZFLX7JC.js | AI (source-diff): Minified React/Ink help view component; long lines are normal for bundled UI code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-UFNKCPUB.js | AI (source-diff): Large bundled CLI chunk; sample shows standard minified utilities, no malicious network/exec patterns. | ai | |
| source-diff | obfuscated-file:dist/HelpView-WVCLJJMT.js | AI (source-diff): Standard minified ESM bundle output from a build tool; content is clearly a CLI help view component. | ai | |
| source-diff | net-exec-file:dist/chunk-PSB4TGW4.js | AI (source-diff): Bundled CLI tool; network refs are URL strings in help/config, not dynamic fetch+eval dropper patterns. | ai | |
| source-diff | net-exec-file:dist/chunk-L2HVRWIT.js | AI (source-diff): Minified bundle for a CLI tool; sample shows standard library code (brace-expansion, path utils), not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/HelpView-DMXQKJYW.js | AI (source-diff): Minified React/Ink help-screen component; content is benign CLI UI code. | ai | |
| source-diff | net-exec-file:dist/chunk-V7M72PLH.js | AI (source-diff): Bundled CLI dist file; sample shows standard library code (brace-expansion, path utils), not malicious dropper behavior. | ai | |
| source-diff | large-new-source-files | AI (source-diff): CLI tool with bundled dist; large file count is expected for this package type. | ai | |
| source-diff | obfuscated-file:dist/HelpView-SIIWVMWF.js | AI (source-diff): Minified React/Ink component rendering CLI help text; matches declared LambdaTest/kane-cli repo and product. | ai | |
| source-diff | net-exec-file:dist/chunk-D3YS6JDD.js | AI (source-diff): Bundled CLI utility code (glob/braces parsing); network calls are part of legitimate CLI functionality, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/HelpView-QSQBGS3R.js | AI (source-diff): Minified bundle from LambdaTest's kane-cli; sample content matches legitimate CLI help view UI. | ai | |
| source-diff | net-exec-file:dist/chunk-GNMGQOGV.js | AI (source-diff): Bundled CLI output; sample shows standard library code (glob/brace-expansion), not dropper/loader malware. | ai | |
| phantom-deps | phantom-dep:open | AI (phantom-deps): Declared dependency used via dynamic imports in CLI framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Declared dependency used via dynamic imports in CLI framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:archiver | AI (phantom-deps): Declared implicit runtime binary dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:sharp | AI (phantom-deps): Declared implicit runtime binary dependency; stable for this package. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Declared dependency used via dynamic imports in CLI framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Declared dependency used via dynamic imports in CLI framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Declared dependency used via dynamic imports in CLI framework; stable pattern. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 0.5.0 | 10 / 0 | |
| 0.4.10 | 8 / 0 | |
| 0.4.9 | 8 / 0 | |
| 0.4.8 | 8 / 0 | |
| 0.4.7 | 8 / 0 | |
| 0.4.6 | 8 / 0 | |
| 0.4.5 | 8 / 0 | |
| 0.4.4 | 8 / 0 | |
| 0.4.3 | 8 / 0 | |
| 0.4.2 | 8 / 0 | |
| 0.4.1 | 7 / 0 | |
| 0.4.0 | 7 / 0 | |
| 0.3.7 | 7 / 0 | |
| 0.3.6 | 7 / 0 | |
| 0.3.5 | 7 / 0 | |
| 0.3.4 | 7 / 0 | |
| 0.3.3 | 7 / 0 | |
| 0.3.2 | 7 / 0 | |
| 0.3.1 | 7 / 0 | |
| 0.3.0 | 7 / 0 | |
| 0.2.11 | 7 / 0 | |
| 0.2.10 | 7 / 0 | |
| 0.2.9 | 7 / 0 | |
| 0.2.8 | 7 / 0 | |
| 0.2.7 | 7 / 0 | |
| 0.2.6 | 7 / 0 | |
| 0.2.5 | 7 / 0 | |
| 0.2.4 | 7 / 0 | |
| 0.2.3 | 7 / 0 | |
| 0.2.2 | 7 / 0 | |
| 0.2.1 | 7 / 0 | |
| 0.2.0 | 7 / 0 |
v0.5.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.10
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.9
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.8
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.