# @bryanapellanes/bam.js@1.0.8 — Threat Briefing Medium risk — threat briefing for npm package @bryanapellanes/bam.js@1.0.8. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 1.0.9 - **License:** MIT ## Risk - **Level:** medium - **Summary:** Held pending complete intel — waiting on Shoulder capability scan ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | none | | filesystem | none | | shell execution | none | ## Trust Signals ### Code Safety - No obfuscated or encoded payloads - No dynamic code execution - No access to sensitive paths - No network activity during install ## Maintainer ## Recommended Action Audit capabilities before use in production.