registry  /  @sentropic/h2a  /  0.84.0

@sentropic/h2a@0.84.0

h2a — the unified CLI + core for human-to-agent coordination.

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis completed at 93.0% confidence. No malicious behavior was detected; 8 low-signal pattern(s) were surfaced and cleared.

Static reason
No blocking static signals were detected.; previous stored version diff introduced dangerous source

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 139 file(s), 923 KB of source, external domains: 127.0.0.1, claude.ai, claude.com

Source & flagged code

2 flagged · loading source
dist/bin.jsView file
40try { L41: rt = (await import(REMOTE_RUNTIME_PKG)); L42: }
Medium
Dynamic Require

Package source references dynamic require/import behavior.

dist/bin.jsView on unpkg · L40
dist/cli.jsView file
matchType = previous_version_dangerous_delta matchedPackage = @sentropic/h2a@0.83.0 matchedIdentity = npm:QHNlbnRyb3BpYy9oMmE:0.83.0 similarity = 0.983 summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta

This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.

dist/cli.jsView on unpkg

Findings

1 High3 Medium4 Low
HighPrevious Version Dangerous Deltadist/cli.js
MediumDynamic Requiredist/bin.js
MediumNetwork
MediumEnvironment Vars
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings