registry  /  replicas-engine  /  0.1.396

replicas-engine@0.1.396

Lightweight API server for Replicas workspaces

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 11 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoEnvironmentVarsFilesystemNetworkShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 20 file(s), 1.24 MB of source, external domains: 169.254.169.254, 169.254.170.2, a.co, api.tryreplicas.com, aws.amazon.com, developers.google.com, developers.linear.app, docs.aws.amazon.com, docs.google.com, docs.replicas.dev, docs.slack.dev, example.com, github.com, gitlab.com, linear.app, news.ycombinator.com, portal.sso, portal.sso-fips, react-native.canny.io, replicas.dev, signin-fips.amazonaws-us-gov.com, slack.com, sts.amazonaws.com, team.slack.com, tryreplicas.com

Source & flagged code

3 flagged · loading source
dist/src/chunk-QE4MMXQA.jsView file
9dateToUtcString, L10: fromBase64, L11: fromUtf8, ... L333: var DEFAULT_PROFILE = "default"; L334: var getProfileName = (init) => init.profile || process.env[ENV_PROFILE] || DEFAULT_PROFILE; L335: ... L358: if (!homeDirCache[homeDirCacheKey]) L359: homeDirCache[homeDirCacheKey] = homedir(); L360: return homeDirCache[homeDirCacheKey]; ... L682: if (region === "*") { L683: console.warn(`@smithy/config-resolver WARN - Please use the caller region instead of "*". See "sigv4a" in https://github.com/aws/aws-sdk-js-v3/blob/main/supplemental-docs/CLIENTS.m... L684: } else {
High
Cloud Metadata Access

Source reaches cloud instance metadata or link-local credential endpoints.

dist/src/chunk-QE4MMXQA.jsView on unpkg · L9
9dateToUtcString, L10: fromBase64, L11: fromUtf8, ... L333: var DEFAULT_PROFILE = "default"; L334: var getProfileName = (init) => init.profile || process.env[ENV_PROFILE] || DEFAULT_PROFILE; L335: ... L358: if (!homeDirCache[homeDirCacheKey]) L359: homeDirCache[homeDirCacheKey] = homedir(); L360: return homeDirCache[homeDirCacheKey]; ... L682: if (region === "*") { L683: console.warn(`@smithy/config-resolver WARN - Please use the caller region instead of "*". See "sigv4a" in https://github.com/aws/aws-sdk-js-v3/blob/main/supplemental-docs/CLIENTS.m... L684: } else {
Low
Weak Crypto

Package source references weak cryptographic algorithms.

dist/src/chunk-QE4MMXQA.jsView on unpkg · L9
scripts/engine-watchdog.shView file
path = scripts/engine-watchdog.sh kind = build_helper sizeBytes = 3679 magicHex = [redacted]
Medium
Ships Build Helper

Package ships non-JavaScript build or shell helper files.

scripts/engine-watchdog.shView on unpkg

Findings

1 High4 Medium6 Low
HighCloud Metadata Accessdist/src/chunk-QE4MMXQA.js
MediumNetwork
MediumEnvironment Vars
MediumShips Build Helperscripts/engine-watchdog.sh
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowWeak Cryptodist/src/chunk-QE4MMXQA.js
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings