npm
ai
1 versiondiscovered · its AI-security audit & verification record by name.
4.0.3auditedresolved-commitverified
coverage →vercel/ai @ d4e5f60718293a4b…
AI security assessmentcleanqwen2.5-7b-instruct
Streaming/tool-call helpers validate schemas before dispatch; no unsafe eval.
Methodology
Sources @ d4e5f60718
README.md, packages/ai/core/generate-text/generate-text.ts, packages/ai/core/tool/tool.ts, packages/ai/core/generate-object/generate-object.ts, packages/ai/streams/stream-data.ts, packages/ai/core/prompt/convert-to-core-messages.ts
Parts 6 files, 11800 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
classes examined: CWE-79
Gate this package in CI
Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.
signet gate --purl pkg:npm/ai@4.0.3 --registry https://signet.seekerslab.com
README badge
Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.
