Typed artifacts, a clear README, and release notes make integration straightforward. Workflow findings around blanket app-token permissions and template injection warrant CI review, while low-confidence cache findings are hygiene concerns.
82%
Total Score
100
100
94
83
100
The repository name does not match the package name and its README does not mention @ai-sdk/xai. Although a monorepo mismatch is ordinary, the lack of a package mention leaves some uncertainty that this repository is the package's exact source.
All 12 workflows were analyzed and all 74 action references are pinned, with 11 workflows using read-only permissions. High-confidence findings report blanket GitHub App token permissions and possible template injection; low-confidence cache-poisoning findings are hygiene concerns, and no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@ai-sdk/provider Version 4.0.21 | — | — |
@ai-sdk/provider-utils Version 5.0.53 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.