Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 21 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
11 flagged · loading sourceA single source file combines environment access, network access, and code or shell execution; review context before blocking.
studio-server.mjsView on unpkg · L2Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
studio-server.mjsView on unpkg · L2Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
studio-server.mjsView on unpkg · L2Package source references weak cryptographic algorithms.
studio-server.mjsView on unpkg · L2This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/launch.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/launch.mjsView on unpkg · L4Package source references a known benign dynamic code generation pattern.
studio-assets/entries/client-editor-router.jsView on unpkg · L48Package ships high-entropy non-source blobs.
studio-assets/templates/fonts/InterVariable.woff2View on unpkgPackage contains source files above the static scanner size ceiling.
studio-assets/entries/editor.jsView on unpkg