Package Health

@ai-sdk/policy-opa

Latest 1.0.130NPMNPM

68%

Total Score

caution

Active maintenance and strong provenance are offset by workflow risks and a repository that does not clearly identify this package.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditdanger

All 13 workflows were analyzed and all action references are pinned, but release-notifications.yml combines a workflow_run trigger with an untrusted checkout, creating a meaningful workflow risk. Two workflows grant top-level write access, and high-confidence blanket GitHub App permissions and template-injection findings add caution; the cache findings are low-confidence hygiene issues.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention @ai-sdk/policy-opa. The package is clearly represented in the artifact and monorepo file context, but the missing README mention leaves some ownership ambiguity.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-141243 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
New
@ai-sdk/policy-opa is vulnerable to Missing Authorization in versions 1.0.0 - 1.0.18.
1.0.0 - 1.0.18
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@ai-sdk/provider
Version 4.0.24
—
—
@ai-sdk/provider-utils
Version 5.0.56
—
—

Weekly Downloads

Info

Last Published
10 hours ago
Created
4 months ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform