Static Scan Results
scanned 20h ago · by rust-scannerStatic analysis flagged 14 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
7 flagged · loading sourcePackage contains a possible secret pattern.
dist/platform/security/user-auth.jsView on unpkg · L175Package source references a known benign dynamic code generation pattern.
dist/platform/tools/read/media.jsView on unpkg · L259Package source references dynamic require/import behavior.
dist/client-auth/android-keystore-token-store.jsView on unpkg · L35Package source references weak cryptographic algorithms.
dist/platform/adapters/telephony/index.jsView on unpkg · L13Source writes installer persistence such as shell profile or service configuration.
dist/platform/runtime/sandbox/provisioning.jsView on unpkg · L2Source reaches cloud instance metadata or link-local credential endpoints.
dist/platform/tools/fetch/trust-tiers.jsView on unpkg · L15Package ships WebAssembly modules.
vendor/bash-language-server/tree-sitter-bash.wasmView on unpkg