Building my npx business card

  • Do these npx business cards run arbitrary code on your computer?

  • Terminal business cards are a nice idea, but RCE business cards are just asking for trouble. Instead of npx, what happened to good'ol curl? Something like

    $ curl ashley.dev

    Some decades ago, we had finger (https://en.wikipedia.org/wiki/Finger_%28protocol%29) which is designed for this very use case. Sadly it's no longer installed by default with most distros:

    $ finger @ashley.dev

  • Reminds me of JAPH [0] - a tiny Perl program that was used in email/newsgroup signature to give it personal touch.

    [0] https://www.perlmonks.org/?node_id=412464

  • This would be a great advertisement for security consulting.

    "I was just able to run arbitrary code on your computer. Here is a sample of your recent browser history. Let me tell you help you mitigate your security vulnerabilities."

  • Ooh, free real estate, let's colonize and gentrify package management