An embedded development environment for mcs51/stm8/avr/cortex-m/riscv on VsCode.
- capability exposure inferred + 22
- tool safety inferred + 5
- trust mitigators mixed − 5
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 10h ago · see ecosystem CVEs →
- B · 19 → B · 22
- B · 31 → B · 19
- C · 38 → B · 31
- A · 0 → C · 38
No known CVEs for this server.
- medium dangerous code
dynamic exec: eval(), indirect eval
analyzed commit 7e16b50 · analyzer v33 · 4d ago
danger signals4
- dynamic code execution eval() github0null-eide-7e16b50/res/html/cmsis_wizard_view/js/app.js :1
nan"===typ)return disp_val;var real_val=eval("".concat(num).concat(disp_inf.operate.operator).concat(disp_inf.operate.val));return isN - dynamic code execution indirect eval github0null-eide-7e16b50/res/html/mem_layout_view/js/chunk-vendors.js :1
}();try{n=n||Function("return this")()||(0,eval)("this")}catch(t){"object"==typeof window&&(n=window)}t.exports=n}])}))},8935:function(t,e,n){"use strict";n(4633);var r=Object.freeze({});function o(t) - dynamic code execution indirect eval github0null-eide-7e16b50/res/html/simple_config_ui/js/chunk-vendors.js :1
}();try{n=n||Function("return this")()||(0,eval)("this")}catch(t){"object"==typeof window&&(n=window)}t.exports=n}])}))},6369:function(t,e,n){"use strict";n(4633);var r=Object.freeze({});function o(t) - dynamic code execution eval() github0null-eide-7e16b50/src/CmsisConfigParser.ts :805
let disp_val = eval(`${num}${operator}${item.var_disp_inf.operate.val}`)
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of github0null.