registry  /  @sleepy-ai/cli  /  0.1.13

@sleepy-ai/cli@0.1.13

Sleepy Code: Where Models and Agents Co-Evolve

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 8 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
Filesystem
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 2.54 KB of source

Source & flagged code

5 flagged · loading source
package.jsonView file
scripts.postinstall = bun ./postinstall.mjs || node ./postinstall.mjs
High
Install Time Lifecycle Scripts

Package defines install-time lifecycle scripts.

package.jsonView on unpkg
scripts.postinstall = bun ./postinstall.mjs || node ./postinstall.mjs
Medium
Ambiguous Install Lifecycle Script

Install-time lifecycle script is not statically allowlisted and needs review.

package.jsonView on unpkg
sleepy-ai-cli-0.1.13.tgzView file
path = sleepy-ai-cli-0.1.13.tgz kind = high_entropy_blob sizeBytes = 6251 magicHex = [redacted]
High
Ships High Entropy Blob

Package ships high-entropy non-source blobs.

sleepy-ai-cli-0.1.13.tgzView on unpkg
path = sleepy-ai-cli-0.1.13.tgz kind = compressed_blob sizeBytes = 6251 magicHex = [redacted]
Medium
Ships Compressed Blob

Package ships compressed or archive-like blobs.

sleepy-ai-cli-0.1.13.tgzView on unpkg
path = sleepy-ai-cli-0.1.13.tgz kind = nested_archive_needs_inspection sizeBytes = 6251 magicHex = [redacted]
Low
Nested Archive Needs Inspection

Package ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.

sleepy-ai-cli-0.1.13.tgzView on unpkg

Findings

2 High3 Medium3 Low
HighInstall Time Lifecycle Scriptspackage.json
HighShips High Entropy Blobsleepy-ai-cli-0.1.13.tgz
MediumAmbiguous Install Lifecycle Scriptpackage.json
MediumShips Compressed Blobsleepy-ai-cli-0.1.13.tgz
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowNested Archive Needs Inspectionsleepy-ai-cli-0.1.13.tgz