Ssd 2
High
- Confidence
- 99% confidence
- Finding
- The comments explicitly describe avoiding the installer scanner's detection rules by restructuring code and even avoiding sensitive substrings so the scanner will not flag the package. Deliberately engineering around a security scanner is dangerous because it defeats a trust control meant to warn users about risky install behavior, and in this context it increases suspicion that the package author is trying to conceal security-relevant behavior from review and policy enforcement.
