Static Scan Results
scanned 3h ago · by rust-scannerStatic analysis flagged 18 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
12 flagged · loading sourcePackage contains a critical-looking secret pattern.
mcps/unreal_mcp/.env.productionView on unpkgPackage source references child process execution.
mcps/unreal_mcp/tests/test-runner.mjsView on unpkg · L771Package source references shell execution.
mcps/unreal_mcp/src/tools/handlers/pipeline/pipeline-ubt-discovery.tsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
mcps/unreal_mcp/src/utils/commands/command-validator.tsView on unpkg · L35Package source references dynamic require/import behavior.
mcps/adobe_uxp_mcp/plugins/photoshop/index.jsView on unpkg · L1Package source references weak cryptographic algorithms.
mcps/unreal_mcp/src/automation/request-tracker.tsView on unpkg · L16Package source invokes a package manager install command at runtime.
installer.jsView on unpkg · L267Package ships non-JavaScript build or shell helper files.
mcps/unreal_mcp/scripts/package-plugin.batView on unpkgPackage ships high-entropy non-source blobs.
skills/global_config/web-artifacts-builder/scripts/shadcn-components.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
skills/global_config/web-artifacts-builder/scripts/shadcn-components.tar.gzView on unpkgHardcoded password in skills/global_config/playwright-skill/lib/helpers.js
skills/global_config/playwright-skill/lib/helpers.jsView on unpkg · L208Hardcoded password in skills/global_legacy/playwright-skill/lib/helpers.js
skills/global_legacy/playwright-skill/lib/helpers.jsView on unpkg · L208