Static Scan Results
scanned 4h ago · by rust-scannerStatic analysis flagged 50 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
41 flagged · loading sourcePackage contains a critical-looking secret pattern.
dist/dist-BJQ4qJgE.jsView on unpkg · L20273Package source references weak cryptographic algorithms.
dist/dist-BJQ4qJgE.jsView on unpkg · L5Package source references child process execution.
dist/ensure-local-gateway-B2qYYNsm.jsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/daemon-runtime-jkMiwykI.jsView on unpkg · L8Package source references dynamic code evaluation.
dist/plugin-sdk/photon_rs-DWHUUvNo.jsView on unpkg · L4179Package source references dynamic require/import behavior.
dist/event-streams-Rl1ERUF4.jsView on unpkg · L481Package source executes code through a VM context API.
dist/event-streams-Rl1ERUF4.jsView on unpkg · L44Source writes installer persistence such as shell profile or service configuration.
dist/config-guard-_bkiEZ2R.jsView on unpkg · L302Source reaches cloud instance metadata or link-local credential endpoints.
dist/plugin-sdk/dist-cjs-0eT73s39.jsView on unpkg · L64Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/gateway-cli-C-KfNrgk.jsView on unpkg · L59A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/gateway-cli-C-KfNrgk.jsView on unpkgSource contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/tui-KKclAOTp.jsView on unpkg · L26Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/tui-KKclAOTp.jsView on unpkg · L26Package ships non-JavaScript build or shell helper files.
skills/model-usage/scripts/model_usage.pyView on unpkgPackage contains source files above the static scanner size ceiling.
dist/pw-ai-ByKRZUzk.jsView on unpkgAWS access key ID in dist/plugin-sdk/dist-C2SauqMb.js
dist/plugin-sdk/dist-C2SauqMb.jsView on unpkg · L22264Hardcoded password in docs/zh-CN/help/faq.md
docs/zh-CN/help/faq.mdView on unpkg · L2191Hardcoded password in docs/zh-CN/gateway/tailscale.md
docs/zh-CN/gateway/tailscale.mdView on unpkg · L80Hardcoded password in docs/zh-CN/gateway/configuration.md
docs/zh-CN/gateway/configuration.mdView on unpkg · L2967Hardcoded password in docs/zh-CN/channels/bluebubbles.md
docs/zh-CN/channels/bluebubbles.mdView on unpkg · L43Hardcoded password in docs/gateway/tailscale.md
docs/gateway/tailscale.mdView on unpkg · L81Hardcoded password in docs/gateway/configuration.md
docs/gateway/configuration.mdView on unpkg · L3050Hardcoded password in docs/channels/bluebubbles.md
docs/channels/bluebubbles.mdView on unpkg · L37Hardcoded password in extensions/bluebubbles/src/attachments.test.ts
extensions/bluebubbles/src/attachments.test.tsView on unpkg · L34Hardcoded password in extensions/bluebubbles/src/attachments.test.ts
extensions/bluebubbles/src/attachments.test.tsView on unpkg · L44Hardcoded password in extensions/bluebubbles/src/attachments.test.ts
extensions/bluebubbles/src/attachments.test.tsView on unpkg · L76Hardcoded password in extensions/bluebubbles/src/attachments.test.ts
extensions/bluebubbles/src/attachments.test.tsView on unpkg · L98Hardcoded password in extensions/bluebubbles/src/attachments.test.ts
extensions/bluebubbles/src/attachments.test.tsView on unpkg · L228Hardcoded password in extensions/bluebubbles/src/send.test.ts
extensions/bluebubbles/src/send.test.tsView on unpkg · L847Hardcoded password in extensions/bluebubbles/src/monitor.test.ts
extensions/bluebubbles/src/monitor.test.tsView on unpkg · L241Hardcoded password in extensions/bluebubbles/src/monitor.test.ts
extensions/bluebubbles/src/monitor.test.tsView on unpkg · L439Hardcoded password in extensions/bluebubbles/src/monitor.test.ts
extensions/bluebubbles/src/monitor.test.tsView on unpkg · L475Hardcoded password in extensions/bluebubbles/src/monitor.test.ts
extensions/bluebubbles/src/monitor.test.tsView on unpkg · L515Hardcoded password in extensions/bluebubbles/src/monitor.test.ts
extensions/bluebubbles/src/monitor.test.tsView on unpkg · L550Hardcoded password in extensions/bluebubbles/src/actions.test.ts
extensions/bluebubbles/src/actions.test.tsView on unpkg · L72Hardcoded password in extensions/bluebubbles/src/actions.test.ts
extensions/bluebubbles/src/actions.test.tsView on unpkg · L86Hardcoded password in extensions/bluebubbles/src/actions.test.ts
extensions/bluebubbles/src/actions.test.tsView on unpkg · L159