The package includes clear usage documentation, types, licensing, release notes, and npm provenance. Its source project is active and broadly maintained, though the repository link does not identify this package directly and workflow permissions need care.
76%
Total Score
100
100
90
88
100
The name resembles the independently published cline package and the README explicitly identifies Cline, which can confuse consumers, although zero artifact overlap indicates this is an adapter rather than a copied package.
The repository name does not match the package and its README does not mention the package, so package-to-repository ownership is less transparent; the monorepo context partly explains the mismatch but does not remove the gap.
All 12 workflows were analyzed with no untrusted checkout or script-injection findings, and 11 use read-only permissions. Two high-confidence github-app findings and one top-level write workflow are workflow-hygiene concerns, while the cache findings are low-confidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-891128 New @ai-sdk/harness-cline is vulnerable to Path Traversal in versions 1.0.0 - 1.0.7. | 1.0.0 - 1.0.7 | High |
| Dependency | Last Release | Score |
|---|---|---|
@cline/core Version ^0.0.83 | — | — |
@cline/agents Version ^0.0.83 | — | — |
@ai-sdk/harness Version 1.0.133 | — | — |
@ai-sdk/provider Version 4.0.19 | — | — |
@ai-sdk/provider-utils Version 5.0.51 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.