Back to plugin
Pluginv0.7.1
Static analysis security
TradeAlpha Open Platform · Deterministic local checks for risky code patterns and metadata mismatches.
Scanner verdict
SuspiciousApr 29, 2026, 4:41 AM
- Summary
- Detected: suspicious.env_credential_access
- Reason codes
- suspicious.env_credential_access
- Engine
- v2.4.2
Evidence
criticalscripts/get-realtime-news.js:52
Environment variable access combined with network send.
const envToken = process.env[TOKEN_ENV_NAME]?.trim();
