Static Scan Results
scanned 23h ago · by rust-scannerStatic analysis flagged 8 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessEnvironmentVarsFilesystemNetwork
HighEntropyStringsUrlStrings
Source & flagged code
1 flagged · loading sourcepackage.jsonView file
•Remote tarball dependency specs: @lloyal-labs/corpus-app@https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.2.0.tgz, @lloyal-labs/web-app@https://apps.lloyal.ai/v1/bundles/lloyal__web-1.2.0.tgz
Medium
Remote Tarball Dependency
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgFindings
3 Medium5 Low
MediumNetwork
MediumEnvironment Vars
MediumRemote Tarball Dependencypackage.json
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings