registry  /  @quantum-ai/roo-code-cli  /  0.3.0

@quantum-ai/roo-code-cli@0.3.0

Static Scan Results

scanned 2d ago · by rust-scanner

Static analysis completed at 93.0% confidence. No malicious behavior was detected; 12 low-signal pattern(s) were surfaced and cleared.

Static reason
No blocking static signals were detected.; previous stored version diff introduced dangerous source

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEnvironmentVarsEvalFilesystemShell
Supply chain
HighEntropyStringsUrlStrings
Manifest
NoLicense
scanned 6 file(s), 1.15 MB of source, external domains: api.github.com, api.minimax.io, api.minimaxi.com, api.moonshot.ai, api.moonshot.cn, dev.to, dotenvx.com, feross.org, fireworks.ai, github.com, jimmy.warting.se, platform.minimax.io, raw.githubusercontent.com, sheetjs.com, www.eliostruyf.com
Oversized source lightweight scan
apps/cli/extension/extension.js32.8 MB file, sampled 256 KB
FilesystemChildProcessEnvironmentVarsCryptoHighEntropyStringsUrlStringsdev.todotenvx.comfeross.orggithub.comjimmy.warting.sesheetjs.comwww.eliostruyf.com
apps/cli/extension/workers/countTokens.js2.28 MB file, sampled 256 KB
FilesystemChildProcessEvalShellHighEntropyStrings

Source & flagged code

4 flagged · loading source
apps/cli/extension/wasm_exec_node.jsView file
12globalThis.require = require; L13: globalThis.fs = require("fs"); L14: globalThis.TextEncoder = require("util").TextEncoder;
Medium
Dynamic Require

Package source references dynamic require/import behavior.

apps/cli/extension/wasm_exec_node.jsView on unpkg · L12
apps/cli/extension/tree-sitter-elm.wasmView file
path = apps/cli/extension/tree-sitter-elm.wasm kind = wasm_module sizeBytes = 148886 magicHex = [redacted]
Medium
Ships Wasm Module

Package ships WebAssembly modules.

apps/cli/extension/tree-sitter-elm.wasmView on unpkg
apps/cli/extension/workers/countTokens.jsView file
path = [redacted].js kind = oversized_source_file sizeBytes = 2395419 magicHex = [redacted]
High
Oversized Source File

Package contains source files above the static scanner size ceiling.

apps/cli/extension/workers/countTokens.jsView on unpkg
apps/cli/dist/index.jsView file
matchType = previous_version_dangerous_delta matchedPackage = @quantum-ai/roo-code-cli@0.2.9 matchedIdentity = npm:[redacted]:0.2.9 similarity = 0.750 summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta

This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.

apps/cli/dist/index.jsView on unpkg

Findings

2 High4 Medium6 Low
HighOversized Source Fileapps/cli/extension/workers/countTokens.js
HighPrevious Version Dangerous Deltaapps/cli/dist/index.js
MediumDynamic Requireapps/cli/extension/wasm_exec_node.js
MediumEnvironment Vars
MediumShips Wasm Moduleapps/cli/extension/tree-sitter-elm.wasm
MediumStructural Risk Force Deep Review
LowScripts Present
LowEval
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings
LowNo License