critical
suspicious.env_credential_access
- Location
- dist/index.js:17
- Finding
- Environment variable access combined with network send.
- Evidence
const raw = String(process.env.ADSCENE_API_URL || '').replace(/\/+$/, '');
AdvisoryAudited by Static analysis on May 17, 2026.
Detected: suspicious.env_credential_access
const raw = String(process.env.ADSCENE_API_URL || '').replace(/\/+$/, '');
const raw = String(process.env.ADSCENE_API_URL || '').replace(/\/+$/, '');