Static Scan Results
scanned 4h ago · by rust-scannerStatic analysis flagged 14 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
7 flagged · loading sourcePackage source references child process execution.
bundled/capture-runner.jsView on unpkg · L1232Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
bundled/capture-runner.jsView on unpkg · L192Package source references a known benign dynamic code generation pattern.
bundled/capture-runner.jsView on unpkg · L29320Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
lib/cli.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
lib/cli.jsView on unpkg · L216Package ships non-JavaScript build or shell helper files.
plugin/scripts/gateway-start.shView on unpkg