Static Scan Results
scanned 2d ago · by rust-scannerStatic analysis flagged 17 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
6 flagged · loading sourcePackage source references child process execution.
dist/auto-update-bg.jsView on unpkg · L8Package source invokes a package manager install command at runtime.
dist/auto-update-bg.jsView on unpkg · L30Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunk-JENSKJP6.jsView on unpkg · L12Source writes installer persistence such as shell profile or service configuration.
dist/chunk-JENSKJP6.jsView on unpkg · L12Package ships non-JavaScript build or shell helper files.
skills/hooks/run-hook.cmdView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
dist/cli.jsView on unpkg