Static Scan Results
scanned 4h ago · by rust-scannerStatic analysis flagged 19 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
11 flagged · loading sourcePackage contains a possible secret pattern.
.sinapse-ai/product/templates/engine/elicitation.jsView on unpkg · L26Package source references dynamic require/import behavior.
bin/sinapse.jsView on unpkg · L8This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/commands/install.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
bin/commands/install.jsView on unpkg · L3Package source invokes a package manager install command at runtime.
bin/commands/local.jsView on unpkg · L3Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.claude/hooks/pre-commit-version-check.shView on unpkgPackage ships non-JavaScript build or shell helper files.
.claude/hooks/pre-commit-version-check.shView on unpkgHardcoded password in .sinapse-ai/product/data/supabase-patterns.md
.sinapse-ai/product/data/supabase-patterns.mdView on unpkg · L72Hardcoded password in .sinapse-ai/product/data/supabase-patterns.md
.sinapse-ai/product/data/supabase-patterns.mdView on unpkg · L86