# chai-as-promised@7.1.2 — Threat Briefing High risk — threat briefing for npm package chai-as-promised@7.1.2. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 8.0.2 - **License:** WTFPL ## Risk - **Level:** high - **Summary:** Dormant package revived with maintainer or script changes ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | none | | filesystem | none | | shell execution | none | ## Capabilities ### Other - No dependency lockfile (unpinned installs) [common] ## Key Signals - **** - **** - **** ## Maintainer ## Recommended Action Review before installing in sensitive environments.