AI called this Suspicious at 91.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- package.json: prepare runs "husky install".
- .husky/pre-commit runs npm pre-commit in a consumer Git checkout.
- etc/wildcard.brightcove.com.key is a bundled private-key file, read only by dev-server config.
Evidence against
- No preinstall/install/postinstall hook.
- Hook only invokes lint-staged and tests; no network or shell payload found.
- Runtime API calls use the host StudioModule API for player and URL-shortener functions.
- No credential harvesting, exfiltration, dynamic execution, or persistence found in source.
- build/package.json removes the prepare script for the build distribution.
Behavioral surface
SourceEnvironmentVarsFilesystem
Supply chainHighEntropyStringsMinifiedUrlStrings
scanned 44 file(s), 195 KB of source, external domains: es.studio.support.brightcove.com, fr.studio.support.brightcove.com, ja.studio.support.brightcove.com, ko.studio.support.brightcove.com, localhost.brightcove.com, players.brightcove.net, players.qa.brightcove.net, preview-players.brightcove.net, preview-players.qa.brightcove.net, studio.support.brightcove.com, zh-tw.studio.support.brightcove.com