78%
Total Score
healthy
Frequent releases and active organizational maintenance outweigh workflow hygiene and package-repository reference concerns.
The repository name does not match the package and its README does not mention the package, creating some uncertainty about package-to-repository correspondence; the monorepo context reduces but does not remove that concern.
All 13 workflows were analyzed and all 78 action references are pinned, but one workflow combines workflow_run with an untrusted checkout, two workflows use broad top-level write permissions, and high-confidence blanket GitHub App permissions were found. Low-confidence cache findings are hygiene concerns only.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-633663 New @ai-sdk/harness-deepagents is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.0.132. | 1.0.0 - 1.0.132 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.21.0 | — | — |
@ai-sdk/harness Version 1.0.141 | — | — |
@ai-sdk/provider-utils Version 5.0.56 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.