Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 16 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
8 flagged · loading sourcePackage source references child process execution.
script/postinstall.mjsView on unpkg · L2Package source references dynamic require/import behavior.
script/time.tsView on unpkg · L4Source executes local commands and sends command output to an external endpoint.
src/lsp/server.tsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/lsp/server.tsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/lsp/server.tsView on unpkg · L1Hardcoded password in test/server/auth.test.ts
test/server/auth.test.tsView on unpkg · L47Hardcoded password in test/server/httpapi-listen.test.ts
test/server/httpapi-listen.test.tsView on unpkg · L18