68%
Total Score
caution
Active maintenance and strong provenance are offset by workflow risks and a repository that does not clearly identify this package.
All 13 workflows were analyzed and all action references are pinned, but release-notifications.yml combines a workflow_run trigger with an untrusted checkout, creating a meaningful workflow risk. Two workflows grant top-level write access, and high-confidence blanket GitHub App permissions and template-injection findings add caution; the cache findings are low-confidence hygiene issues.
The repository name does not match the package name and its README does not mention @ai-sdk/policy-opa. The package is clearly represented in the artifact and monorepo file context, but the missing README mention leaves some ownership ambiguity.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-141243 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @ai-sdk/policy-opa is vulnerable to Missing Authorization in versions 1.0.0 - 1.0.18. | 1.0.0 - 1.0.18 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@ai-sdk/provider Version 4.0.24 | — | — |
@ai-sdk/provider-utils Version 5.0.56 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.