registry  /  mandrel  /  1.79.0

mandrel@1.79.0

Claude Code-first opinionated workflow framework: instructions, personas, skills, and SDLC workflows that govern AI coding assistants.

Static Scan Results

scanned 4d ago · by rust-scanner

Static analysis flagged 14 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessDynamicRequireEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 14 file(s), 182 KB of source, external domains: cli.github.com, git-scm.com, github.com, nodejs.org, raw.githubusercontent.com

Source & flagged code

6 flagged · loading source
package.jsonView file
scripts.postinstall = node bin/postinstall.js mandrel sync
High
Install Time Lifecycle Scripts

Package defines install-time lifecycle scripts.

package.jsonView on unpkg
scripts.postinstall = node bin/postinstall.js mandrel sync
Medium
Ambiguous Install Lifecycle Script

Install-time lifecycle script is not statically allowlisted and needs review.

package.jsonView on unpkg
.agents/scripts/lib/qa/redact-evidence.jsView file
53patternName = generic_password severity = medium line = 53 matchedText = password...d]',
Medium
Secret Pattern

Package contains a possible secret pattern.

.agents/scripts/lib/qa/redact-evidence.jsView on unpkg · L53
bin/mandrel.jsView file
109function installedVersion() { L110: const req = createRequire(import.meta.url); L111: const manifest = req('../package.json');
Medium
Dynamic Require

Package source references dynamic require/import behavior.

bin/mandrel.jsView on unpkg · L109
.agents/skills/core/idea-refinement/scripts/idea-refine.shView file
path = .agents/skills/core/idea-refinement/scripts/idea-refine.sh kind = payload_in_excluded_dir sizeBytes = 342 magicHex = [redacted]
High
Payload In Excluded Dir

Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.

.agents/skills/core/idea-refinement/scripts/idea-refine.shView on unpkg
path = .agents/skills/core/idea-refinement/scripts/idea-refine.sh kind = build_helper sizeBytes = 342 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

.agents/skills/core/idea-refinement/scripts/idea-refine.shView on unpkg

Findings

2 High7 Medium5 Low
HighInstall Time Lifecycle Scriptspackage.json
HighPayload In Excluded Dir.agents/skills/core/idea-refinement/scripts/idea-refine.sh
MediumAmbiguous Install Lifecycle Scriptpackage.json
MediumSecret Pattern.agents/scripts/lib/qa/redact-evidence.js
MediumDynamic Requirebin/mandrel.js
MediumNetwork
MediumEnvironment Vars
MediumShips Build Helper.agents/skills/core/idea-refinement/scripts/idea-refine.sh
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings