Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 21 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
13 flagged · loading sourcePackage source references a known benign dynamic code generation pattern.
dist/analyzers/health/actions.jsView on unpkg · L232Package source references dynamic require/import behavior.
dist/constants.jsView on unpkg · L38Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
templates/.devcontainer/post-create.shView on unpkgPackage ships non-JavaScript build or shell helper files.
templates/.devcontainer/post-create.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/tools-cli.jsView on unpkgHardcoded password in dist/analyzers/tools/grep-secrets.js
dist/analyzers/tools/grep-secrets.jsView on unpkg · L135Hardcoded password in dist/analyzers/tools/grep-secrets.js
dist/analyzers/tools/grep-secrets.jsView on unpkg · L146Hardcoded password in dist/analyzers/tools/gitleaks.js
dist/analyzers/tools/gitleaks.jsView on unpkg · L161Hardcoded password in dist/analyzers/security/benign.js
dist/analyzers/security/benign.jsView on unpkg · L10Hardcoded password in dist/analyzers/security/benign.d.ts
dist/analyzers/security/benign.d.tsView on unpkg · L9