Package Health

@genkit-ai/tools-common

Healthy and suitable to depend on. It has frequent releases, active organizational backing, strong repository activity, tests, and clear licensing; the main caveats are missing build provenance, no security policy, and broad workflow permissions.

Latest 1.43.0NPMNPM

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation, trusted publisher identity, or staged publishing is present. The active repository and controlled release workflows provide some context, but they do not compensate for the missing direct provenance of this artifact.

Dangerous workflowscaution

One of 19 workflows uses pull_request_target, but there are no untrusted checkouts or script-injection findings. The isolated workflow pattern is a limited concern rather than a severe project-health issue.

Dependency profilecaution

The package declares 28 runtime dependencies, including substantial server, validation, and utility functionality. This is a meaningful dependency surface to maintain, but the provided signals show no specific dependency failure or instability.

Repo package mentioncaution

The repository name does not match the package and its README does not mention this exact package, which can make package ownership less transparent. The matching organization namespace and monorepo-style repository context reduce, but do not eliminate, that concern.

Security policycaution

The repository has no published security policy. This weakens vulnerability-reporting transparency for a project with a broad runtime dependency and server-related surface.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-745297 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@genkit-ai/tools-common is vulnerable to Path Traversal in versions 0.9.0 - 1.39.0.
0.9.0 - 1.39.0
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
ws
Version ^8.18.3
ajv
Version ^8.12.0
tsx
Version ^4.19.2
zod
Version ^3.22.4
cors
Version ^2.8.5

Weekly Downloads

Info

Last Published
3 days ago
Created
2 years ago
Unpacked Size
6.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform