npm analyzed 0.43.1

task-master-ai

v0.43.1
npm

A task management system for ambitious AI-driven development that doesn't overwhelm and confuse Cursor.

maintainer
crunchyman-ralph
license
MIT WITH Commons-Clause
first seen
2026-05-22
last seen
2026-06-16
releases · 30d
0
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities2 tools
transport stdio counts 2 tools · 0 res · 0 prompts permission surface via code analysis

tools

  • custom

    Variable

  • standard

    15

skills & danger signalsnpm-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed v0.43.1 · analyzer v17 · 2d ago

skills & prompt files 3

danger signals1

  • credential in logscredential in logpackage/dist/dependency-manager-BJq6jWA5.js:87Context:`)),t.orgName&&console.log(B.gray(` Organization: ${t.orgName}`)),t.briefName&&console.log(B.gray(` Brief: ${t.briefName}`))),{success:!0,action:`status`,credentials:{token:e?.access_tok
code evidencev0.43.1 · npm-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

shell / exec 6

  • shell package/dist/ai-services-unified-CsFt27lZ.js :1 import{A as e,C as t,D as n,Et as r,F as i,H as a,I as o,J as s,M as c,N as l,P as u,S as d,T as f,_ as p,a as m,b as h,d as g,ht as ee,j as _,l as v,o as te,p as y,s as ne,ut as b,v as x,yt as S}from
  • shell package/dist/config-manager-DTKWXIqv.js :1 import{t as e}from"./git-utils-DllbRE35.js";import t,{join as n,resolve as r}from"node:path";import i from"chalk";import{createClient as a,isAuthError as o}from"@supabase/supabase-js";import s from"fs
  • shell package/dist/dependency-manager-BJq6jWA5.js :1 import{a as e,i as t,l as n,n as r,t as i}from"./ai-services-unified-CsFt27lZ.js";import{$ as a,A as o,At as s,B as c,Bt as l,C as u,Ct as d,D as f,Dn as p,En as m,Jt as h,Kt as g,L as _,Lt as v,Mt as
  • shell package/dist/git-utils-DllbRE35.js :1 import e from"fs";import t from"path";import{exec as n,execSync as r}from"child_process";import{promisify as i}from"util";const a=i(n);async function o(e){if(!e)throw Error(`projectRoot is required fo
  • shell package/dist/profiles-CvDnJeks.js :1 import{c as e}from"./ai-services-unified-CsFt27lZ.js";import{Bt as t,E as n,Ft as r,Gt as i,Ht as a,It as o,J as s,Pt as c,Ut as l,Vt as u,Wt as d,hn as f,qt as p,vt as m,yt as h}from"./config-manager
  • shell package/index.js :26 import { spawn } from 'child_process';

network 2

  • net package/dist/ai-services-unified-CsFt27lZ.js :1 import{A as e,C as t,D as n,Et as r,F as i,H as a,I as o,J as s,M as c,N as l,P as u,S as d,T as f,_ as p,a as m,b as h,d as g,ht as ee,j as _,l as v,o as te,p as y,s as ne,ut as b,v as x,yt as S}from
  • net package/dist/config-manager-DTKWXIqv.js :2 `),this.logger.debug(`Persisted session to disk (steno)`)}catch(e){this.logger.error(`Failed to persist session:`,e)}}async getItem(e){await this.initPromise;let t=this.storage.get(e)??null;return thi

secrets 3

  • secrets package/dist/ai-services-unified-CsFt27lZ.js :3 • GOOGLE_APPLICATION_CREDENTIALS pointing to a service account JSON file (recommended for production)`);if(!n||typeof n==`string`&&n.trim().length===0)throw new J(`Google Cloud project ID is required
  • secrets package/dist/config-manager-DTKWXIqv.js :2 `),this.logger.debug(`Persisted session to disk (steno)`)}catch(e){this.logger.error(`Failed to persist session:`,e)}}async getItem(e){await this.initPromise;let t=this.storage.get(e)??null;return thi
  • secrets package/dist/dependency-manager-BJq6jWA5.js :242 `),this.action(async()=>{await this.authCommand.executeLogout()})}static register(t){let n=new e;return t.addCommand(n),n}},vi=class{static commands=[{name:`list`,description:`List all tasks with filt

declared dependencies 87

  • @ai-sdk/amazon-bedrock@^3.0.23
  • @ai-sdk/anthropic@^2.0.18
  • @ai-sdk/azure@^2.0.89
  • @ai-sdk/google@^2.0.16
  • @ai-sdk/google-vertex@^3.0.86
  • @ai-sdk/groq@^2.0.21
  • @ai-sdk/mistral@^2.0.16
  • @ai-sdk/openai@^2.0.34
  • @ai-sdk/openai-compatible@^1.0.25
  • @ai-sdk/perplexity@^2.0.10
  • @ai-sdk/provider@^2.0.0
  • @ai-sdk/provider-utils@^3.0.10
  • @ai-sdk/xai@^2.0.22
  • @aws-sdk/credential-providers@^3.895.0
  • @inquirer/search@^3.0.15
  • @openrouter/ai-sdk-provider@^1.2.0
  • @sentry/node@^10.27.0
  • @streamparser/json@^0.0.22
  • @supabase/supabase-js@^2.57.4
  • @types/turndown@^5.0.6
  • ai@^5.0.51
  • ai-sdk-provider-claude-code@^2.2.4
  • ai-sdk-provider-codex-cli@^0.7.0
  • ai-sdk-provider-gemini-cli@^1.4.0
  • ajv@^8.17.1
  • ajv-formats@^3.0.1
  • boxen@^8.0.1
  • chalk@5.6.2
  • cli-highlight@^2.1.11
  • cli-progress@^3.12.0
  • cli-table3@^0.6.5
  • commander@^12.1.0
  • cors@^2.8.5
  • date-fns@^4.1.0
  • dotenv@^16.6.1
  • express@^4.21.2
  • fastmcp@^3.23.1
  • figlet@^1.8.0
  • fs-extra@^11.3.0
  • fuse.js@^7.1.0
  • gpt-tokens@^1.3.14
  • gradient-string@^3.0.0
  • helmet@^8.1.0
  • inquirer@^12.5.0
  • jsonc-parser@^3.3.1
  • jsonrepair@^3.13.0
  • jsonwebtoken@^9.0.2
  • lru-cache@^10.2.0
  • marked@^15.0.12
  • marked-terminal@^7.3.0
  • ollama-ai-provider-v2@^1.3.1
  • open@^10.2.0
  • ora@^8.2.0
  • proper-lockfile@^4.1.2
  • simple-git@^3.28.0
  • steno@^4.0.2
  • terminal-link@^5.0.0
  • turndown@^7.2.2
  • undici@^7.16.0
  • uuid@^11.1.0
  • zod@^4.1.12
  • @anthropic-ai/mcpb@^2.1.2
  • @biomejs/biome@^1.9.4
  • @changesets/changelog-github@^0.5.1
  • @changesets/cli@^2.28.1
  • @manypkg/cli@^0.25.1
  • @tm/ai-sdk-provider-grok-cli@*
  • @tm/cli@*
  • @types/fs-extra@^11.0.4
  • @types/jest@^29.5.14
  • @types/marked-terminal@^6.1.1
  • @vitest/coverage-v8@^4.0.10
  • concurrently@^9.2.1
  • cross-env@^10.0.0
  • execa@^8.0.1
  • jest@^29.7.0
  • jest-environment-node@^29.7.0
  • mock-fs@^5.5.0
  • prettier@^3.5.3
  • supertest@^7.1.0
  • ts-jest@^29.4.2
  • tsdown@^0.15.2
  • tsx@^4.20.4
  • turbo@2.5.6
  • typescript@^5.9.2
  • @anthropic-ai/claude-code@^2.0.59
  • @biomejs/cli-linux-x64@^1.9.4