# jnwb@0.1.5 — Threat Briefing High risk — threat briefing for npm package jnwb@0.1.5. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 0.1.5 - **License:** MIT ## Risk - **Level:** high - **Summary:** Dev dependency karma-phantomjs-launcher has CRITICAL alert — developer machines at risk, not production ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | server | | filesystem | both | | shell execution | exec | ## Capabilities ### Execution - CLI command installation [common] - Shell execution [unusual] ### Environment - Environment variable access [common] ### Other - Hidden process execution [common] ### Filesystem - Filesystem read [common] - Filesystem write [common] ### Network - Network server [common] ### System - Process control [common] ## Maintainer ## Recommended Action Review before installing in sensitive environments.