Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 23 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
12 flagged · loading sourcePackage contains a critical-looking secret pattern.
dist/utils/providerConfig.jsView on unpkg · L715RSA private key in dist/utils/providerConfig.js
dist/utils/providerConfig.jsView on unpkg · L715Package source references dynamic require/import behavior.
dist/auth/sessionManager.jsView on unpkg · L120Source appears to send environment or credential material to an external endpoint.
dist/providers/googleVertex.jsView on unpkg · L304Package ships non-JavaScript build or shell helper files.
scripts/observability/manage-local-openobserve.shView on unpkgPackage contains source files above the static scanner size ceiling.
dist/browser/neurolink.min.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/utils/conversationMemory.jsView on unpkgHardcoded password in dist/processors/errors/errorSerializer.js
dist/processors/errors/errorSerializer.jsView on unpkg · L471Hardcoded password in dist/processors/errors/errorSerializer.d.ts
dist/processors/errors/errorSerializer.d.tsView on unpkg · L75RSA private key in dist/lib/utils/providerConfig.js
dist/lib/utils/providerConfig.jsView on unpkg · L715Hardcoded password in dist/lib/processors/errors/errorSerializer.js
dist/lib/processors/errors/errorSerializer.jsView on unpkg · L471Hardcoded password in dist/lib/processors/errors/errorSerializer.d.ts
dist/lib/processors/errors/errorSerializer.d.tsView on unpkg · L75