registry  /  @hyperframes/studio  /  0.7.22

@hyperframes/studio@0.7.22

Browser-based composition editor UI for Hyperframes. Provides a visual timeline, code editor, and live preview for building video compositions.

Static Scan Results

scanned 3d ago · by rust-scanner

Static analysis flagged 11 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessFilesystemNetwork
Supply chain
HighEntropyStringsMinifiedObfuscatedTelemetryUrlStrings
Manifest
NoLicense
scanned 447 file(s), 5.50 MB of source, external domains: 127.0.0.1, aomediacodec.github.io, cdn.example.com, cdn.jsdelivr.net, example.com, fonts.googleapis.com, fonts.gstatic.com, github.com, react.dev, studio.local, us.i.posthog.com, www.w3.org, www.webmproject.org
Oversized source lightweight scan
dist/assets/index-B4h4u7eW.js3.01 MB file, sampled 256 KB
NetworkChildProcessObfuscatedHighEntropyStringsMinifiedTelemetryUrlStringsgithub.comreact.devwww.w3.org

Source & flagged code

2 flagged · loading source
dist/index.jsView file
184fill: "none", L185: xmlns: "http://www.w3.org/2000/svg", L186: "aria-hidden": "true", ... L1209: if (!raw) return {}; L1210: const parsed = JSON.parse(raw); L1211: if (!isRecord2(parsed)) return {}; ... L1455: try { L1456: return import.meta.env.DEV === true; L1457: } catch { ... L1541: headers: { "Content-Type": "application/json" }, L1542: body: JSON.stringify({ api_key: POSTHOG_API_KEY, batch }), L1543: signal: controller.signal
High
Sandbox Evasion Gated Capability

Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.

dist/index.jsView on unpkg · L184
dist/assets/index-B4h4u7eW.jsView file
path = dist/assets/index-B4h4u7eW.js kind = oversized_source_file sizeBytes = 3158365 magicHex = [redacted]
High
Oversized Source File

Package contains source files above the static scanner size ceiling.

dist/assets/index-B4h4u7eW.jsView on unpkg

Findings

2 High2 Medium7 Low
HighSandbox Evasion Gated Capabilitydist/index.js
HighOversized Source Filedist/assets/index-B4h4u7eW.js
MediumNetwork
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowObfuscated
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings
LowNo License