Static Scan Results
scanned 2d ago · by rust-scannerStatic analysis flagged 20 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
11 flagged · loading sourceSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/prjct.cjsView on unpkg · L10Package source references dynamic require/import behavior.
bin/prjct.cjsView on unpkg · L10This package version adds a dangerous source file absent from the previous stored version.
dist/bin/prjct-hooks.mjsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/prjct-hooks.mjsView on unpkg · L8Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/prjct-hooks.mjsView on unpkg · L9Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bin/prjct-core.mjsView on unpkg · L5Package source references a known benign dynamic code generation pattern.
dist/bin/prjct-core.mjsView on unpkg · L2171Package source references weak cryptographic algorithms.
dist/bin/prjct.mjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
scripts/install.shView on unpkg