Package Health

@ai-sdk/harness-claude-code

Latest 1.0.145NPMNPM

78%

Total Score

healthy

Frequent releases and strong project backing outweigh workflow-audit and package-to-repository transparency concerns.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, leaving some uncertainty about package-to-repository mapping despite the organization-backed monorepo context.

Workflow auditcaution

All 13 workflows were analyzed and action references are pinned, but the audit found an untrusted checkout in a workflow_run workflow, blanket GitHub App permissions, and a high-confidence template-injection pattern; low-confidence cache findings are only hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-601428 New
@ai-sdk/harness-claude-code is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.0.136.
1.0.0 - 1.0.136
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
ws
Version ^8.21.0
—
—
@ai-sdk/harness
Version 1.0.141
—
—
@ai-sdk/provider
Version 4.0.24
—
—
@ai-sdk/provider-utils
Version 5.0.56
—
—

Weekly Downloads

Info

Last Published
9 hours ago
Created
4 months ago
Unpacked Size
1.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform