84%
Total Score
healthy
A fast-moving, licensed release from an active, well-backed project with verified provenance.
All 13 workflows were analyzed and all action references are pinned, but one workflow combines workflow_run with an untrusted checkout, and two workflows use broad app-token permissions. The low-confidence cache findings are hygiene concerns rather than strong evidence by themselves.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-108451 New @ai-sdk/harness-acp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 1.0.70. | 0.0.1 - 1.0.70 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^8.21.0 | — | — |
@ai-sdk/harness Version 1.0.141 | — | — |
@ai-sdk/provider-utils Version 5.0.56 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.