Static Scan Results
scanned 5h ago · by rust-scannerStatic analysis flagged 15 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
6 flagged · loading sourcePackage source references child process execution.
dist/cli/updater.jsView on unpkg · L18Package source references dynamic require/import behavior.
bin/zelari-code.jsView on unpkg · L21Source exposes local file and command tools to a remote model endpoint.
dist/cli/main.bundled.jsView on unpkg · L201Package source references weak cryptographic algorithms.
dist/cli/main.bundled.jsView on unpkg · L642This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli/workspace/postCouncilHook.jsView on unpkg