208 packages matching “benign”
@onum-releases/sdk
v1.0.3 · 1 month ago
Security PoC placeholder (dependency-confusion / scope-takeover demonstration) - benign, no runtime payload. Uploaded by yash_005 for authorized security research.
1 unknown
@onum-releases/utils
v1.0.3 · 1 month ago
Security PoC placeholder (dependency-confusion / scope-takeover demonstration) - benign, no runtime payload. Uploaded by yash_005 for authorized security research.
No known vulnerabilities
@x9722-1/exist-1783895608
v1.0.0 · 26 days ago
authz-test probe (benign)
No known vulnerabilities
@x9722-1/probe-ctrl-1783895461
v1.0.0 · 26 days ago
authz-test probe (benign)
No known vulnerabilities
@antisoft/figma-make-bb-canary
v0.0.1 · 27 days ago
Benign npm lifecycle canary for authorized Figma Make security testing
No known vulnerabilities
@x9722-1/revtest-1783894905
v1.0.0 · 26 days ago
authz-test probe (benign)
No known vulnerabilities
lifecycle-tester
v1.0.3 · 2 months ago
Contains benign pre and postinstall scripts to enable safe testing of lifecycle script settings in Node, Bun and Deno
No known vulnerabilities
@safepaste/core
v0.3.0 · 4 months ago
Prompt injection detection for AI applications. Lightweight regex-based engine with weighted scoring, benign-context dampening, and zero dependencies.
No known vulnerabilities
nono-postinstall-test
v1.0.2 · 4 months ago
Benign post-install canary package for testing sandbox protections against supply chain attacks
No known vulnerabilities
npmjs-hitscan
v1.0.0 · 9 months ago
A benign package to test various npm security heuristic scanners
No known vulnerabilities
@maaz96/kc-mock-feed
v1.0.1 · 6 months ago
Mock feed data for supply-chain demo (benign).
No known vulnerabilities
@axiorank/redteam-corpus
v0.1.0 · 1 month ago
AxioRank agent red-team corpus: a versioned library of attack scenarios (secrets, injection, destructive ops, kill chains) plus benign controls. Pure data, zero runtime dependencies.
No known vulnerabilities
@turbowarp/ancient-hull.js
v0.2.13 · 11 months ago
Very old version of hull.js with backported security fixes -- do not use in new projects
No known vulnerabilities
@hxntr/toast-vdp-f001-canary
v1.99.99 · 2 months ago
Benign dependency-confusion canary for Toast Intigriti VDP F001. Demonstrates install-time code execution path. Source: see Intigriti report. NO data exfil, NO network calls, NO destructive ops — only console output + a marker file in /tmp.
No known vulnerabilities
yandex-geobase
v2.9.0 · 1 month ago
Dependency confusion security test placeholder. Does not collect data.
1 unknown
friendly-words
v1.3.1 · 2 years ago
The Glitch word list, packaged into an NPM module for easy use.
No known vulnerabilities
benign-win-supply-chain-demo
v1.0.4 · 3 years ago
A small demo app to show how supply chain attacks may be used
No known vulnerabilities
@shoulderdev/mcp-safe-demo
v0.0.1 · 5 months ago
Safe MCP server demo - benign tools with no attack patterns, for comparison testing
No known vulnerabilities
hermes-paperclip-adapter
v0.3.0 · 4 months ago
Paperclip adapter for Hermes Agent — run Hermes as a managed employee in a Paperclip company
No known vulnerabilities
@paperclipai/hermes-paperclip-adapter
v2026.722.0 · 16 days ago
Paperclip adapters for Hermes Agent local CLI and Hermes Gateway HTTP/SSE runs
No known vulnerabilities