Static Scan Results
scanned 3h ago · by rust-scannerStatic analysis flagged 9 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.; previous stored version diff introduced dangerous source
Decision evidence
public snapshotBehavioral surface
ChildProcessEnvironmentVarsFilesystemNetwork
HighEntropyStringsUrlStrings
Source & flagged code
2 flagged · loading sourcepackage.jsonView file
•Remote tarball dependency specs: @lloyal-labs/corpus-app@https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.2.0.tgz, @lloyal-labs/web-app@https://apps.lloyal.ai/v1/bundles/lloyal__web-1.2.0.tgz
Medium
Remote Tarball Dependency
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgdist/bundle.mjsView file
•matchType = previous_version_dangerous_delta
matchedPackage = reasoning.run@0.4.0
matchedIdentity = npm:cmVhc29uaW5nLnJ1bg:0.4.0
similarity = 0.500
summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bundle.mjsView on unpkgFindings
1 High3 Medium5 Low
HighPrevious Version Dangerous Deltadist/bundle.mjs
MediumNetwork
MediumEnvironment Vars
MediumRemote Tarball Dependencypackage.json
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings