Static Scan Results
scanned 42m ago · by rust-scannerStatic analysis flagged 29 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
21 flagged · loading sourcePackage contains a critical-looking secret pattern.
doctor-UYMLO2DE.jsView on unpkg · L4685GitHub OAuth access token in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L4806GitHub OAuth access token in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L4807GitHub OAuth access token in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L4808Supabase service role key (JWT) in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L5724Supabase service role key (JWT) in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L5725Supabase service role key (JWT) in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L6603Supabase service role key (JWT) in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L6605Supabase service role key (JWT) in doctor-UYMLO2DE.js
doctor-UYMLO2DE.jsView on unpkg · L6942Source writes installer persistence such as shell profile or service configuration.
esm-SRH3OR6L.jsView on unpkg · L127Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L122