registry  /  @permission-slip/cli  /  0.1.19

@permission-slip/cli@0.1.19

Agent-facing CLI for Permission Slip — register, verify, and interact with Permission Slip servers

Static Scan Results

scanned 3d ago · by rust-scanner

Static analysis flagged 14 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStrings
ManifestNo manifest risk signals triggered.
scanned 29 file(s), 80.5 KB of source

Source & flagged code

8 flagged · loading source
dist/auth/keys.jsView file
41patternName = private_key_rsa severity = critical line = 41 matchedText = * Suppor...vely
Critical
Critical Secret

Package contains a critical-looking secret pattern.

dist/auth/keys.jsView on unpkg · L41
41patternName = private_key_rsa severity = critical line = 41 matchedText = * Suppor...vely
Critical
Secret Pattern

RSA private key in dist/auth/keys.js

dist/auth/keys.jsView on unpkg · L41
42patternName = private_key_openssh severity = critical line = 42 matchedText = * unders...--`,
Critical
Secret Pattern

OpenSSH private key in dist/auth/keys.js

dist/auth/keys.jsView on unpkg · L42
62patternName = private_key_openssh severity = critical line = 62 matchedText = .replace... "")
Critical
Secret Pattern

OpenSSH private key in dist/auth/keys.js

dist/auth/keys.jsView on unpkg · L62
161patternName = private_key_rsa severity = critical line = 161 matchedText = * NOTE: ... the
Critical
Secret Pattern

RSA private key in dist/auth/keys.js

dist/auth/keys.jsView on unpkg · L161
162patternName = private_key_openssh severity = critical line = 162 matchedText = * OpenSS...de's
Critical
Secret Pattern

OpenSSH private key in dist/auth/keys.js

dist/auth/keys.jsView on unpkg · L162
dist/auth/keys.d.tsView file
28patternName = private_key_rsa severity = critical line = 28 matchedText = * Suppor...vely
Critical
Secret Pattern

RSA private key in dist/auth/keys.d.ts

dist/auth/keys.d.tsView on unpkg · L28
29patternName = private_key_openssh severity = critical line = 29 matchedText = * unders...--`,
Critical
Secret Pattern

OpenSSH private key in dist/auth/keys.d.ts

dist/auth/keys.d.tsView on unpkg · L29

Findings

8 Critical2 Medium4 Low
CriticalCritical Secretdist/auth/keys.js
CriticalSecret Patterndist/auth/keys.js
CriticalSecret Patterndist/auth/keys.js
CriticalSecret Patterndist/auth/keys.js
CriticalSecret Patterndist/auth/keys.js
CriticalSecret Patterndist/auth/keys.js
CriticalSecret Patterndist/auth/keys.d.ts
CriticalSecret Patterndist/auth/keys.d.ts
MediumNetwork
MediumEnvironment Vars
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings