106var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L106 106var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
CriticalDownload Execute
Source downloads or fetches remote code and executes it.
dist/index.jsView on unpkg · L106 106Trigger-reachable chain: manifest.main -> dist/index.js
L106: var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L106 27683* **CWE-78 Command Injection**:
L27684: - \`exec()\`, \`spawn()\`, or \`execSync()\` with unsanitized user input.
L27685: - \`child_process\` usage without strict argument separation.
•Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/index.js:
function readLineBreak(state) {
readLineBreak(state);
readLineBreak(state);
readLineBreak(state);
import { existsSync as existsSync34, mkdirSync as mkdirSync13, readFileSync as readFileSync28, unlinkSync as unlinkSync7, writeFileSync as writeFileSync15 } from "fs";
writeFileSync15(filePath, content, "utf-8");
agent-browser open api.example.com --headers '{"Authorization": "Bearer <token>"}'
- **World baseURL**: The generated \`world.ts\` MUST set \`baseURL: process.env.BDD_BASE_URL || 'http://localhost:4000'\` in \`browser.newContext()\` so \`page.goto('/login')\` res...
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkg 106var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
HighCloud Metadata Access
Source reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L106 106var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
HighObfuscated Payload Loader
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L106 26256- **TypeScript loader**: Add \`{ module: ['tsx/esm'] }\` to \`requireModule\` so \`tsx\` transpiles \`.ts\` files on import.
L26257: - **World baseURL**: The generated \`world.ts\` MUST set \`baseURL: process.env.BDD_BASE_URL || 'http://localhost:4000'\` in \`browser.newContext()\` so \`page.goto('/login')\` res...
L26258:
...
L27683: * **CWE-78 Command Injection**:
L27684: - \`exec()\`, \`spawn()\`, or \`execSync()\` with unsanitized user input.
L27685: - \`child_process\` usage without strict argument separation.
...
L44907: try {
L44908: const content = readFileSync(cacheFile, "utf-8");
L44909: const data = JSON.parse(content);
...
L99958: ### Phase 2: Automated Scanning
L99959: Run available tools in order. If a tool is not installed, note it and continue with the next.
L99960
HighRemote Agent Bridge
Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L26256 106Trigger-reachable credential exfiltration chain: manifest.main -> dist/index.js
L106: var init_js_yaml = __esm(() => {
L107: /*! js-yaml 4.2.0 https://github.com/nodeca/js-yaml @license MIT */
L108: __create2 = Object.create;
...
L536: for (;index < max; index++) {
L537: if (!isHexCode(data.charCodeAt(index)))
L538: return false;
...
L2846: if (!match) {
L2847: return { data: {}, body: content, hadFrontmatter: false, parseError: false };
L2848: }
...
L3025: }
L3026: if (typeof process !== "undefined" && process.platform) {
L3027: return process.platform === "win32";
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L106 •stage = ast_semantic_analysis; reason = ast_trace_path_limit_exceeded; limitedFiles = 2
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index.jsView on unpkg