React Orchestrator

Security checks across static analysis, malware telemetry, and agentic risk

Overview

No artifact-backed suspicious behavior was available in the accessible review context, but local artifact inspection was blocked.

Install only after a successful artifact review can inspect metadata.json and artifact/ directly; this result is low confidence because the local command sandbox failed before file contents could be read.

Static analysis

Dangerous exec

Critical
Finding
Shell command execution detected (child_process).

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.