registry  /  @deepstorm/cli  /  0.2.3

@deepstorm/cli@0.2.3

DeepStorm CLI — 一键配置项目开发环境

Static Scan Results

scanned 4h ago · by rust-scanner

Static analysis flagged 11 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoEnvironmentVarsFilesystemShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 8 file(s), 412 KB of source, external domains: json-schema.org, registry.npmjs.org

Source & flagged code

3 flagged · loading source
dist/cli.jsView file
8121var path19 = __toESM(require("node:path")); L8122: var import_node_child_process = require("node:child_process"); L8123:
High
Child Process

Package source references child process execution.

dist/cli.jsView on unpkg · L8121
8481try { L8482: (0, import_node_child_process.execSync)("npm install -g @deepstorm/cli@latest", { stdio: "inherit" }); L8483: console.log(`
High
Runtime Package Install

Package source invokes a package manager install command at runtime.

dist/cli.jsView on unpkg · L8481
dist/hooks/reef-scope-check.shView file
path = dist/hooks/reef-scope-check.sh kind = build_helper sizeBytes = 12007 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

dist/hooks/reef-scope-check.shView on unpkg

Findings

3 High3 Medium5 Low
HighChild Processdist/cli.js
HighShell
HighRuntime Package Installdist/cli.js
MediumEnvironment Vars
MediumShips Build Helperdist/hooks/reef-scope-check.sh
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings