Static Scan Results
scanned 3h ago · by rust-scannerStatic analysis flagged 12 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessCryptoEnvironmentVarsFilesystemNetworkShellWebSocket
HighEntropyStringsUrlStrings
NoLicense
Source & flagged code
3 flagged · loading sourcebin/orbital.jsView file
1#!/usr/bin/env node
L2: import { spawn } from 'node:child_process';
L3: import fs from 'node:fs';
High
mod/common.mjsView file
494} else if (process.platform === 'win32') {
L495: proc = spawn('cmd.exe', ['/c', cmd, ...args], { shell: false });
L496: } else {
High
mod/setup.jsView file
41const child = spawn(
L42: 'cmd.exe',
L43: ['/c', 'start', '"offckb-devnet"', '/min', 'npx', '@offckb/cli', 'node'],
...
L56: 'bash',
L57: ['-lc', 'nohup npx @offckb/cli node >/tmp/offckb-devnet.log 2>&1 < /dev/null &'],
L58: {
High
Runtime Package Install
Package source invokes a package manager install command at runtime.
mod/setup.jsView on unpkg · L41Findings
3 High3 Medium6 Low
HighChild Processbin/orbital.js
HighShellmod/common.mjs
HighRuntime Package Installmod/setup.js
MediumNetwork
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings
LowNo License