Static Scan Results
scanned 3d ago · by rust-scannerStatic analysis flagged 15 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
7 flagged · loading sourcePackage source references child process execution.
bin/cookie-helper.jsView on unpkg · L13Package source references dynamic require/import behavior.
bin/cookie-helper.jsView on unpkg · L13Source writes installer persistence such as shell profile or service configuration.
bin/scheduler/launchd.jsView on unpkg · L4A single source file combines environment access, network access, and code or shell execution; review context before blocking.
mcp/dist/screencast.jsView on unpkg · L12Package source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L813Package ships non-JavaScript build or shell helper files.
skill/dm-outreach-reddit.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version.
mcp/dist/index.jsView on unpkg