registry  /  @cynos-ai/engineer  /  0.21.7

@cynos-ai/engineer@0.21.7

Cynos — an autonomous AI engineering runtime with evidence-based completion verification.

Static Scan Results

scanned 4d ago · by rust-scanner

Static analysis flagged 13 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessEnvironmentVarsFilesystem
Supply chain
HighEntropyStringsMinifiedObfuscatedTelemetryTrivial
Manifest
NoLicenseWildcardDependency
scanned 1 file(s), 562 KB of source

Source & flagged code

3 flagged · loading source
index.jsView file
1'use strict';function _0x177f(_0x251682,_0x18283d){_0x251682=_0x251682-0x15a;const _0x310a68=_0x310a();let _0x177f40=_0x310a68[_0x251682];if(_0x177f['hDpOMT']===undefined){var _0x4...
High
Child Process

Package source references child process execution.

index.jsView on unpkg · L1
1'use strict';function _0x177f(_0x251682,_0x18283d){_0x251682=_0x251682-0x15a;const _0x310a68=_0x310a();let _0x177f40=_0x310a68[_0x251682];if(_0x177f['hDpOMT']===undefined){var _0x4...
High
Same File Env Network Execution

A single source file combines environment access, network access, and code or shell execution; review context before blocking.

index.jsView on unpkg · L1
1'use strict';function _0x177f(_0x251682,_0x18283d){_0x251682=_0x251682-0x15a;const _0x310a68=_0x310a();let _0x177f40=_0x310a68[_0x251682];if(_0x177f['hDpOMT']===undefined){var _0x4...
High
Obfuscated Payload Loader

Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.

index.jsView on unpkg · L1

Findings

4 High3 Medium6 Low
HighChild Processindex.js
HighSame File Env Network Executionindex.js
HighObfuscated Payload Loaderindex.js
HighObfuscated
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
MediumWildcard Dependency
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowTelemetry
LowNo License