Static Scan Results
scanned 2d ago · by rust-scannerStatic analysis flagged 14 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
7 flagged · loading sourcePackage contains a critical-looking secret pattern.
evals/integration/test_hook_category_behaviors.shView on unpkg · L155AWS access key ID in evals/integration/test_hook_category_behaviors.sh
evals/integration/test_hook_category_behaviors.shView on unpkg · L155Package source references dynamic require/import behavior.
packaging/conformance/run-conformance.jsView on unpkg · L22Package source references weak cryptographic algorithms.
context/scripts/hooks/stop-format-typecheck.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
evals/ci/run-baseline.shView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/fixtures/veritas-governance-adapter/fake-veritas-secret-fail.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/check-content-boundary.cjsView on unpkg