Dynamic code execution detected.
Critical
- Code
- suspicious.dynamic_code_execution
- Location
- dist/index.js:6024
- Evidence
return new Function(""), !0;
Security audit
Security checks for vulnerabilities and agentic risk
This academic search plugin mostly matches its description, but it declares silent default auto-updates and sends research inputs to ai4scholar.net.
Review and preferably disable the autoUpdate setting before installing. Use a dedicated ai4scholar.net API key, avoid submitting confidential manuscripts or figures unless you trust the provider, and ask the publisher to clarify or remove the silent updater and compiled Python cache artifacts.
Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.obfuscated_code
return new Function(""), !0;process.env.HOME ?? "~",
return Uint8Array.fromBase64 ? Uint8Array.fromBase64(str) : stringToBytes(atob(str));