Static Scan Results
scanned 6h ago · by rust-scannerStatic analysis flagged 21 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
12 flagged · loading sourcePackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a critical-looking secret pattern.
skills/credential-leak-detector/SKILL.mdView on unpkg · L27AWS access key ID in skills/credential-leak-detector/SKILL.md
skills/credential-leak-detector/SKILL.mdView on unpkg · L27GitHub personal access token in skills/credential-leak-detector/SKILL.md
skills/credential-leak-detector/SKILL.mdView on unpkg · L28RSA private key in skills/credential-leak-detector/SKILL.md
skills/credential-leak-detector/SKILL.mdView on unpkg · L31Package source references child process execution.
dist/threadline/PipeSessionSpawner.jsView on unpkg · L15Package source references shell execution.
dist/threadline/PipeSessionSpawner.jsView on unpkg · L281Package source references dynamic require/import behavior.
dist/memory/SemanticMemory.jsView on unpkg · L428A single source file combines environment access, network access, and code or shell execution; review context before blocking.
skills/spec-converge/scripts/publish-spec-review.mjsView on unpkg · L20Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/core/upgradeAnnouncement.jsView on unpkg · L19Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/hooks/free-text-guard.shView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/hooks/free-text-guard.shView on unpkg