registry  /  @cynos-ai/engineer  /  0.22.0

@cynos-ai/engineer@0.22.0

Cynos — an autonomous AI engineering runtime with evidence-based completion verification.

Static Scan Results

scanned 4h ago · by rust-scanner

Static analysis flagged 16 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessEnvironmentVarsFilesystemNetwork
Supply chain
HighEntropyStringsMinifiedObfuscatedTelemetryTrivialUrlStrings
Manifest
NoLicenseWildcardDependency
scanned 1 file(s), 669 KB of source, external domains: api.tavily.com

Source & flagged code

4 flagged · loading source
index.jsView file
1'use strict';const _0x490b62=_0x7db6,_0x5de2b0=_0x7db6;(function(_0x4269da,_0x32566a){const _0x22ae09=_0x7db6,_0x7c9e6e=_0x7db6,_0x4d76b9=_0x4269da();while(!![]){try{const _0x5644f...
High
Child Process

Package source references child process execution.

index.jsView on unpkg · L1
1'use strict';const _0x490b62=_0x7db6,_0x5de2b0=_0x7db6;(function(_0x4269da,_0x32566a){const _0x22ae09=_0x7db6,_0x7c9e6e=_0x7db6,_0x4d76b9=_0x4269da();while(!![]){try{const _0x5644f...
High
Same File Env Network Execution

A single source file combines environment access, network access, and code or shell execution; review context before blocking.

index.jsView on unpkg · L1
1'use strict';const _0x490b62=_0x7db6,_0x5de2b0=_0x7db6;(function(_0x4269da,_0x32566a){const _0x22ae09=_0x7db6,_0x7c9e6e=_0x7db6,_0x4d76b9=_0x4269da();while(!![]){try{const _0x5644f...
High
Command Output Exfiltration

Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.

index.jsView on unpkg · L1
1'use strict';const _0x490b62=_0x7db6,_0x5de2b0=_0x7db6;(function(_0x4269da,_0x32566a){const _0x22ae09=_0x7db6,_0x7c9e6e=_0x7db6,_0x4d76b9=_0x4269da();while(!![]){try{const _0x5644f...
High
Obfuscated Payload Loader

Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.

index.jsView on unpkg · L1

Findings

5 High4 Medium7 Low
HighChild Processindex.js
HighSame File Env Network Executionindex.js
HighCommand Output Exfiltrationindex.js
HighObfuscated Payload Loaderindex.js
HighObfuscated
MediumNetwork
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
MediumWildcard Dependency
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings
LowNo License