78%
Total Score
healthy
Frequent releases and strong project backing outweigh workflow-audit and package-to-repository transparency concerns.
The repository name does not match the package and its README does not mention the package, leaving some uncertainty about package-to-repository mapping despite the organization-backed monorepo context.
All 13 workflows were analyzed and action references are pinned, but the audit found an untrusted checkout in a workflow_run workflow, blanket GitHub App permissions, and a high-confidence template-injection pattern; low-confidence cache findings are only hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-601428 New @ai-sdk/harness-claude-code is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.0.136. | 1.0.0 - 1.0.136 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^8.21.0 | — | — |
@ai-sdk/harness Version 1.0.141 | — | — |
@ai-sdk/provider Version 4.0.24 | — | — |
@ai-sdk/provider-utils Version 5.0.56 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.