registry  /  @cynos-ai/engineer  /  0.21.10

@cynos-ai/engineer@0.21.10

Cynos — an autonomous AI engineering runtime with evidence-based completion verification.

Static Scan Results

scanned 2d ago · by rust-scanner

Static analysis flagged 15 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessEnvironmentVarsFilesystemNetwork
Supply chain
HighEntropyStringsMinifiedObfuscatedTelemetryTrivial
Manifest
NoLicenseWildcardDependency
scanned 1 file(s), 589 KB of source

Source & flagged code

4 flagged · loading source
index.jsView file
1'use strict';const _0x3f2b99=_0x2489,_0x4e7b50=_0x2489;(function(_0x3704fc,_0x117758){const _0x3f9649=_0x2489,_0x408c29=_0x2489,_0x416ee6=_0x3704fc();while(!![]){try{const _0x233cb...
High
Child Process

Package source references child process execution.

index.jsView on unpkg · L1
1'use strict';const _0x3f2b99=_0x2489,_0x4e7b50=_0x2489;(function(_0x3704fc,_0x117758){const _0x3f9649=_0x2489,_0x408c29=_0x2489,_0x416ee6=_0x3704fc();while(!![]){try{const _0x233cb...
High
Same File Env Network Execution

A single source file combines environment access, network access, and code or shell execution; review context before blocking.

index.jsView on unpkg · L1
1'use strict';const _0x3f2b99=_0x2489,_0x4e7b50=_0x2489;(function(_0x3704fc,_0x117758){const _0x3f9649=_0x2489,_0x408c29=_0x2489,_0x416ee6=_0x3704fc();while(!![]){try{const _0x233cb...
High
Command Output Exfiltration

Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.

index.jsView on unpkg · L1
1'use strict';const _0x3f2b99=_0x2489,_0x4e7b50=_0x2489;(function(_0x3704fc,_0x117758){const _0x3f9649=_0x2489,_0x408c29=_0x2489,_0x416ee6=_0x3704fc();while(!![]){try{const _0x233cb...
High
Obfuscated Payload Loader

Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.

index.jsView on unpkg · L1

Findings

5 High4 Medium6 Low
HighChild Processindex.js
HighSame File Env Network Executionindex.js
HighCommand Output Exfiltrationindex.js
HighObfuscated Payload Loaderindex.js
HighObfuscated
MediumNetwork
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
MediumWildcard Dependency
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowTelemetry
LowNo License