Static Scan Results
scanned 3d ago · by rust-scannerStatic analysis flagged 30 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
22 flagged · loading sourcePackage contains a critical-looking secret pattern.
doctor-ZXNAHH7L.jsView on unpkg · L4682GitHub OAuth access token in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L4803GitHub OAuth access token in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L4804GitHub OAuth access token in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L4805Supabase service role key (JWT) in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L5721Supabase service role key (JWT) in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L5722Supabase service role key (JWT) in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L6600Supabase service role key (JWT) in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L6602Supabase service role key (JWT) in doctor-ZXNAHH7L.js
doctor-ZXNAHH7L.jsView on unpkg · L6939Source writes installer persistence such as shell profile or service configuration.
esm-SRH3OR6L.jsView on unpkg · L127Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L124This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
generate-OLW5YVNN.jsView on unpkg