registry  /  @sentropic/h2a  /  0.83.0

@sentropic/h2a@0.83.0

h2a — the unified CLI + core for human-to-agent coordination.

Static Scan Results

scanned 1d ago · by rust-scanner

Static analysis completed at 65.0% confidence. No malicious behavior was detected; 7 low-signal pattern(s) were surfaced and cleared.

Static reason
No blocking static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 139 file(s), 914 KB of source, external domains: 127.0.0.1, claude.ai, claude.com

Source & flagged code

1 flagged · loading source
dist/bin.jsView file
40try { L41: rt = (await import(REMOTE_RUNTIME_PKG)); L42: }
Medium
Dynamic Require

Package source references dynamic require/import behavior.

dist/bin.jsView on unpkg · L40

Findings

3 Medium4 Low
MediumDynamic Requiredist/bin.js
MediumNetwork
MediumEnvironment Vars
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings