Static Scan Results
scanned 3d ago · by rust-scannerStatic analysis flagged 14 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessCryptoDynamicRequireEnvironmentVarsFilesystemNetworkShell
HighEntropyStringsMinifiedObfuscatedTelemetryUrlStrings
NoLicense
Oversized source lightweight scan
dist/cli.js8.63 MB file, sampled 256 KB
FilesystemNetworkChildProcessEnvironmentVarsCryptoShellDynamicRequireHighEntropyStringsUrlStrings127.0.0.1api.heygen.comapi2.heygen.comcdn.example.comexample.com
dist/studio/assets/index-B4h4u7eW.js3.01 MB file, sampled 256 KB
NetworkChildProcessObfuscatedHighEntropyStringsMinifiedTelemetryUrlStringsgithub.comreact.devwww.w3.org
Source & flagged code
3 flagged · loading sourcedist/studio/index.jsView file
184fill: "none",
L185: xmlns: "http://www.w3.org/2000/svg",
L186: "aria-hidden": "true",
...
L1209: if (!raw) return {};
L1210: const parsed = JSON.parse(raw);
L1211: if (!isRecord2(parsed)) return {};
...
L1455: try {
L1456: return import.meta.env.DEV === true;
L1457: } catch {
...
L1541: headers: { "Content-Type": "application/json" },
L1542: body: JSON.stringify({ api_key: POSTHOG_API_KEY, batch }),
L1543: signal: controller.signal
High
Sandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/studio/index.jsView on unpkg · L184dist/studio/assets/index-B4h4u7eW.jsView file
•path = dist/studio/assets/index-B4h4u7eW.js
kind = oversized_source_file
sizeBytes = 3158365
magicHex = [redacted]
High
Oversized Source File
Package contains source files above the static scanner size ceiling.
dist/studio/assets/index-B4h4u7eW.jsView on unpkgdist/cli.jsView file
•path = dist/cli.js
kind = oversized_cli_entrypoint
sizeBytes = 9052564
magicHex = [redacted]
Medium
Oversized Cli Entrypoint
Package contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkgFindings
2 High5 Medium7 Low
HighSandbox Evasion Gated Capabilitydist/studio/index.js
HighOversized Source Filedist/studio/assets/index-B4h4u7eW.js
MediumDynamic Require
MediumNetwork
MediumEnvironment Vars
MediumOversized Cli Entrypointdist/cli.js
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowObfuscated
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings
LowNo License