Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 18 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
10 flagged · loading sourcePackage source references a known benign dynamic code generation pattern.
dashboard/assets/mammoth.browser-imoN_kHU.jsView on unpkg · L25Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
plugins/channel-telegram-client.jsView on unpkg · L1Package source references dynamic require/import behavior.
plugins/channel-telegram-client.jsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
scripts/uninstall.mjsView on unpkg · L30Package ships WebAssembly modules.
dashboard/assets/occt-import-js-BhHfLpto.wasmView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/self-update.ps1View on unpkgPackage ships high-entropy non-source blobs.
dashboard/assets/jetbrains-mono-vietnamese-600-normal-OWROknRo.woffView on unpkgPackage contains source files above the static scanner size ceiling.
swarmai.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
swarmai.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg