Static Scan Results
scanned 3d ago · by rust-scannerStatic analysis flagged 16 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
5 flagged · loading sourcePackage source references child process execution.
dist/auto-update-bg.jsView on unpkg · L8Package source invokes a package manager install command at runtime.
dist/auto-update-bg.jsView on unpkg · L30Source reaches cloud instance metadata or link-local credential endpoints.
dist/cli.jsView on unpkg · L16Source writes installer persistence such as shell profile or service configuration.
dist/cli.jsView on unpkg · L16Package ships non-JavaScript build or shell helper files.
skills/hooks/run-hook.cmdView on unpkg