Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 7 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessDynamicRequireEnvironmentVarsFilesystem
Source & flagged code
3 flagged · loading sourcedist/dependency/dependency-manager.jsView file
6exports.DependencyManager = void 0;
L7: const child_process_1 = require("child_process");
L8: const path_1 = __importDefault(require("path"));
High
Child Process
Package source references child process execution.
dist/dependency/dependency-manager.jsView on unpkg · L6109try {
L110: (0, child_process_1.execSync)('npm install --ignore-scripts --no-audit --no-fund --loglevel=error', {
L111: cwd: handlerPath,
High
Runtime Package Install
Package source invokes a package manager install command at runtime.
dist/dependency/dependency-manager.jsView on unpkg · L109dist/validator/package-validator.jsView file
6exports.PackageValidator = void 0;
L7: const path_1 = __importDefault(require("path"));
L8: /**
Medium
Dynamic Require
Package source references dynamic require/import behavior.
dist/validator/package-validator.jsView on unpkg · L6Findings
2 High3 Medium2 Low
HighChild Processdist/dependency/dependency-manager.js
HighRuntime Package Installdist/dependency/dependency-manager.js
MediumDynamic Requiredist/validator/package-validator.js
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem