Dynamic code execution detected.
- Code
- suspicious.dynamic_code_execution
- Location
- dist/index.js:30702
- Evidence
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent DebugBundle integration, with disclosed credential use and optional management actions that users should allowlist carefully.
Install this only for agents that should access DebugBundle project data. Provide the narrowest useful token, review optional mutation tools before allowlisting them, and be especially cautious with project deletion, token creation or revocation, billing capacity changes, member management, GitHub, Slack, webhook, alert, probe, and analytics settings tools.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);const llhttpWasmData = process.env.JEST_WORKER_ID ? require_llhttp_wasm() : void 0;
var BEARER = [REDACTED])\s+[A-Za-z0-9._~+\/-]{6,}/gi;rawAuthState = await readFile(authFilePath);