registry  /  @gakwaya/app-agent-workflow  /  1.3.0

@gakwaya/app-agent-workflow@1.3.0

Complex workflow orchestration with state management and error recovery

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 5 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
Eval
Supply chain
HighEntropyStrings
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 22.6 KB of source

Source & flagged code

2 flagged · loading source
dist/index.jsView file
22if (_0x1e10["mkUisN"] === void 0) { L23: var _0x41829e = function(_0x34d2ba) { L24: const _0x504049 = "[redacted]+/=";
High
Obfuscated Payload Loader

Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.

dist/index.jsView on unpkg · L22
273}); L274: return new Function("return " + _0x3d56e7)(); L275: } catch {
Low
Eval

Package source references a known benign dynamic code generation pattern.

dist/index.jsView on unpkg · L273

Findings

1 High1 Medium3 Low
HighObfuscated Payload Loaderdist/index.js
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvaldist/index.js
LowHigh Entropy Strings