110var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L110 110var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
CriticalDownload Execute
Source downloads or fetches remote code and executes it.
dist/index.jsView on unpkg · L110 110Trigger-reachable chain: manifest.main -> dist/index.js
L110: var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L110 •matchType = previous_version_dangerous_delta
matchedPackage = opencode-matrixx@2.6.13
matchedIdentity = npm:b3BlbmNvZGUtbWF0cml4eA:2.6.13
similarity = 0.500
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg 27687* **CWE-78 Command Injection**:
L27688: - \`exec()\`, \`spawn()\`, or \`execSync()\` with unsanitized user input.
L27689: - \`child_process\` usage without strict argument separation.
23221L23222: **Windows (PowerShell):**
L23223: \`\`\`powershell
27692- \`JSON.parse()\` on untrusted input without schema validation.
L27693: - \`eval()\` or \`new Function()\` with user-controlled strings.
L27694: - Unsafe YAML or XML parsing.
•Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/index.js:
function readLineBreak(state) {
readLineBreak(state);
readLineBreak(state);
readLineBreak(state);
import { existsSync as existsSync41, mkdirSync as mkdirSync17, readFileSync as readFileSync37, unlinkSync as unlinkSync9, writeFileSync as writeFileSync20 } from "fs";
writeFileSync20(filePath, content, "utf-8");
agent-browser open api.example.com --headers '{"Authorization": "Bearer <token>"}'
- **World baseURL**: The generated \`world.ts\` MUST set \`baseURL: process.env.BDD_BASE_URL || 'http://localhost:4000'\` in \`browser.newContext()\` so \`page.goto('/login')\` res...
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkg 110var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
HighCloud Metadata Access
Source reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L110 110var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
HighObfuscated Payload Loader
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L110 26260- **TypeScript loader**: Add \`{ module: ['tsx/esm'] }\` to \`requireModule\` so \`tsx\` transpiles \`.ts\` files on import.
L26261: - **World baseURL**: The generated \`world.ts\` MUST set \`baseURL: process.env.BDD_BASE_URL || 'http://localhost:4000'\` in \`browser.newContext()\` so \`page.goto('/login')\` res...
L26262:
...
L27687: * **CWE-78 Command Injection**:
L27688: - \`exec()\`, \`spawn()\`, or \`execSync()\` with unsanitized user input.
L27689: - \`child_process\` usage without strict argument separation.
...
L44908: try {
L44909: const content = readFileSync(cacheFile, "utf-8");
L44910: const data = JSON.parse(content);
...
L103203: ### Phase 2: Automated Scanning
L103204: Run available tools in order. If a tool is not installed, note it and continue with the next.
L103
HighRemote Agent Bridge
Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L26260 110Trigger-reachable credential exfiltration chain: manifest.main -> dist/index.js
L110: var init_js_yaml = __esm(() => {
L111: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L112: __create2 = Object.create;
...
L540: for (;index < max; index++) {
L541: if (!isHexCode(data.charCodeAt(index)))
L542: return false;
...
L2850: if (!match) {
L2851: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2852: }
...
L3029: }
L3030: if (typeof process !== "undefined" && process.platform) {
L3031: return process.platform === "win32";
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L110 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 2
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.jsView on unpkg