Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 23 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
16 flagged · loading sourcePackage contains a critical-looking secret pattern.
mcps/unreal_mcp/.env.productionView on unpkgPackage source references child process execution.
mcps/davinci-resolve-mcp/bin/davinci-resolve-mcp.mjsView on unpkg · L2Package source references shell execution.
mcps/unreal_mcp/src/tools/handlers/pipeline/pipeline-ubt-discovery.tsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
mcps/unreal_mcp/src/utils/commands/command-validator.tsView on unpkg · L35Package source references dynamic require/import behavior.
mcps/adobe_uxp_mcp/plugins/photoshop/index.jsView on unpkg · L1Package source references weak cryptographic algorithms.
mcps/unreal_mcp/src/automation/request-tracker.tsView on unpkg · L16Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
mcps/tdmcp/scripts/setup.mjsView on unpkg · L7Package source invokes a package manager install command at runtime.
mcps/RhinoMCP/connector/build.mjsView on unpkg · L32Package ships native binary artifacts.
mcps/computer-use-mcp/computer-use-napi.darwin-arm64.nodeView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
mcps/davinci-resolve-mcp/tests/test_resolve21_actions.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
mcps/davinci-resolve-mcp/tests/test_resolve21_actions.pyView on unpkgPackage ships compressed or archive-like blobs.
skills/global_config/web-artifacts-builder/scripts/shadcn-components.tar.gzView on unpkgPackage ships high-entropy non-source blobs.
mcps/RhinoMCP/art/logo.afdesignView on unpkgHardcoded password in mcps/tdmcp/tests/unit/macroRecorder.test.ts
mcps/tdmcp/tests/unit/macroRecorder.test.tsView on unpkg · L107Hardcoded password in skills/global_config/playwright-skill/lib/helpers.js
skills/global_config/playwright-skill/lib/helpers.jsView on unpkg · L208Hardcoded password in skills/global_legacy/playwright-skill/lib/helpers.js
skills/global_legacy/playwright-skill/lib/helpers.jsView on unpkg · L208