Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 25 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
15 flagged · loading sourcePackage contains a critical-looking secret pattern.
dist/src/compiled/experimental-ai-sdk-code-mode/index.jsView on unpkg · L4AWS access key ID in dist/src/compiled/experimental-ai-sdk-code-mode/index.js
dist/src/compiled/experimental-ai-sdk-code-mode/index.jsView on unpkg · L4Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/eve.jsView on unpkg · L2Package source references dynamic require/import behavior.
bin/eve.jsView on unpkg · L8Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/src/compiled/gray-matter/index.jsView on unpkg · L44Package source references a known benign dynamic code generation pattern.
dist/src/compiled/gray-matter/index.jsView on unpkg · L43Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/src/compiled/@workflow/core/runtime.jsView on unpkg · L1Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/src/compiled/@workflow/core/runtime.jsView on unpkg · L1Package source executes code through a VM context API.
dist/src/compiled/@workflow/core/runtime.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/src/internal/authored-module-loader.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/src/internal/nitro/host/start-production-server.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/compiled/@vercel/sandbox/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/src/runtime/connections/mcp-client.jsView on unpkgRSA private key in dist/src/compiled/jose/index.js
dist/src/compiled/jose/index.jsView on unpkg · L2