registry  /  @sentropic/h2a  /  0.81.0

@sentropic/h2a@0.81.0

h2a — the unified CLI + core for human-to-agent coordination.

Static Scan Results

scanned 5d ago · by rust-scanner

Static analysis completed at 65.0% confidence. No malicious behavior was detected; 7 low-signal pattern(s) were surfaced and cleared.

Static reason
No blocking static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 126 file(s), 850 KB of source, external domains: claude.ai, claude.com

Source & flagged code

1 flagged · loading source
dist/bin.jsView file
41try { L42: rt = (await import(REMOTE_RUNTIME_PKG)); L43: }
Medium
Dynamic Require

Package source references dynamic require/import behavior.

dist/bin.jsView on unpkg · L41

Findings

3 Medium4 Low
MediumDynamic Requiredist/bin.js
MediumNetwork
MediumEnvironment Vars
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings