Static Scan Results
scanned 3h ago · by rust-scannerStatic analysis flagged 30 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
22 flagged · loading sourcePackage contains a critical-looking secret pattern.
doctor-D23JFSPJ.jsView on unpkg · L4685GitHub OAuth access token in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L4806GitHub OAuth access token in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L4807GitHub OAuth access token in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L4808Supabase service role key (JWT) in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L5724Supabase service role key (JWT) in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L5725Supabase service role key (JWT) in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L6603Supabase service role key (JWT) in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L6605Supabase service role key (JWT) in doctor-D23JFSPJ.js
doctor-D23JFSPJ.jsView on unpkg · L6942Source writes installer persistence such as shell profile or service configuration.
esm-SRH3OR6L.jsView on unpkg · L127Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L122This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
slack-S5LL2S4M.jsView on unpkg