•matchType = previous_version_dangerous_delta
matchedPackage = @weppy/roblox-mcp@2.17.1
matchedIdentity = npm:QHdlcHB5L3JvYmxveC1tY3A:2.17.1
similarity = 0.419
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg 104\r
L105: `+n)}function vl(t,e,n,r,i,a){if(t.listenerCount("wsClientError")){let o=new Error(i);Error.captureStackTrace(o,vl),t.emit("wsClientError",o,n,e)}else Jh(n,r,i,a)}});import TQ from...
L106: `)){if(/^\s*#/.test(e))continue;let n=/^\s*root\s*=\s*(?<mountPoint>"[^"]*"|'[^']*'|[^#]*)/.exec(e);if(n)return n.groups.mountPoint.trim().replaceAll(/^["']|["']$/g,"")}}var jQ=ee(...
104\r
L105: `+n)}function vl(t,e,n,r,i,a){if(t.listenerCount("wsClientError")){let o=new Error(i);Error.captureStackTrace(o,vl),t.emit("wsClientError",o,n,e)}else Jh(n,r,i,a)}});import TQ from...
L106: `)){if(/^\s*#/.test(e))continue;let n=/^\s*root\s*=\s*(?<mountPoint>"[^"]*"|'[^']*'|[^#]*)/.exec(e);if(n)return n.groups.mountPoint.trim().replaceAll(/^["']|["']$/g,"")}}var jQ=ee(...
2import { createRequire as __bundleCreateRequire } from 'module';const require = __bundleCreateRequire(import.meta.url);
L3: var Kee=Object.create;var VC=Object.defineProperty;var Yee=Object.getOwnPropertyDescriptor;var Xee=Object.getOwnPropertyNames;var Qee=Object.getPrototypeOf,ete=Object.prototype.has...
L4: `:""},this._extScope=e,this._scope=new hi.Scope({parent:e}),this._nodes=[new DE]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
...
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,le._)`+${i}`);return;case"boolean":r.elseIf((0,le._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,le._)`[${i}]`)}}}function Sse({gen:t,parentData:e,p
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L2 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/index.js:
var Kee=Object.create;var VC=Object.defineProperty;var Yee=Object.getOwnPropertyDescriptor;var Xee=Object.getOwnPropertyNames;var Qee=Object.getPrototypeOf,ete=Object.prototype.has...
`}h5.exports=tbe;function tbe(t,e,n){var r=n||{},i=r.env||process.env.NODE_ENV||"development",a=r.onerror;return function(o){var s,c,l;if(!o&&m5(e)){v1("cannot 404 after headers se...
`;t.dashboardSseClients?.forEach(i=>{i.write(r)})}function M3(t,e){t.dashboardSseClients??=new Set,t.dashboardSseClients.add(e);let n=t.watchSubscriptionHub?.addDashboardSubscriber...
${" ".repeat(e)}}`}throw new TypeError(`Unsupported canonical JSON value: $
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkg 3var Kee=Object.create;var VC=Object.defineProperty;var Yee=Object.getOwnPropertyDescriptor;var Xee=Object.getOwnPropertyNames;var Qee=Object.getPrototypeOf,ete=Object.prototype.has...
L4: `:""},this._extScope=e,this._scope=new hi.Scope({parent:e}),this._nodes=[new DE]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,le._)`+${i}`);return;case"integer":r.elseIf((0,le._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,le._)`+${i}`);return;case"boolean":r.elseIf((0,le._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,le._)`[${i}]`)}}}function
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L3 3Trigger-reachable command-output exfiltration chain: scripts.start -> dist/index.js
L3: var Kee=Object.create;var VC=Object.defineProperty;var Yee=Object.getOwnPropertyDescriptor;var Xee=Object.getOwnPropertyNames;var Qee=Object.getPrototypeOf,ete=Object.prototype.has...
L4: `:""},this._extScope=e,this._scope=new hi.Scope({parent:e}),this._nodes=[new DE]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,le._)`+${i}`);return;case"integer":r.elseIf((0,le._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,le._)`+${i}`);return;case"boolean":r.elseIf((0,le._)`${i} === "false" || ${i} === 0 || ${i} === null`)...
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L3 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.jsView on unpkg 6|| (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,le._)`+${i}`);return;case"boolean":r.elseIf((0,le._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,le._)`[${i}]`)}}}function Sse({gen:t,parentData:e,parentDataProperty:n},r){t.if((0,le._)`${e} !== undefined`,()=>t.assign((0,le...
L8: missingProperty: ${r},
LowEval
Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L6 2import { createRequire as __bundleCreateRequire } from 'module';const require = __bundleCreateRequire(import.meta.url);
L3: var Kee=Object.create;var VC=Object.defineProperty;var Yee=Object.getOwnPropertyDescriptor;var Xee=Object.getOwnPropertyNames;var Qee=Object.getPrototypeOf,ete=Object.prototype.has...
L4: `:""},this._extScope=e,this._scope=new hi.Scope({parent:e}),this._nodes=[new DE]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,le._)`+${i}`);return;case"integer":r.elseIf((0,le._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,le._)`+${i}`);return;case"boolean":r.elseIf((0,le._)`${i} === "fa
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/index.jsView on unpkg · L2