Static Scan Results
scanned 19h ago · by rust-scannerStatic analysis flagged 18 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Decision evidence
public snapshotSource & flagged code
10 flagged · loading sourcePackage source references child process execution.
scripts/run-tests.cjsView on unpkg · L19A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/ui/server/routes/npm.jsView on unpkg · L172Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/ui/server/routes/npm.jsView on unpkg · L6Source mutates package metadata and republishes itself to npm.
scripts/release.jsView on unpkg · L7Package source invokes a package manager install command at runtime.
scripts/release.jsView on unpkg · L25Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
src/ui/public/assets/html.worker-BO6WuOEO.jsView on unpkg · L29Package contains source files above the static scanner size ceiling.
src/ui/public/assets/vendor-SOsdHF7M.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/gitCommit.jsView on unpkg