ghost-scan-code
Audited by Runlayer on Mar 12, 2026
Privilege Escalation
Resource Abuse
Shadow Persistence
Malicious tool definition detected
Description: # Mobile vulnerability validation criteria # Each entry defines what must be true/present/valid for a finding to be worth surfacing # Format: agent > vector > {candidates, cwe, severity, criteria} insecure_data_storage: unencrypted-local: candidates: "File I/O operations (FileOutputStream, writeToFile, File.WriteAllBytes), sensitive data written to files, unencrypted file storage, document directory file writes" cwe: "CWE-312" severity: high: "Credentials, tokens, or financial data
Tool passed security scan
Data Exfiltration
Context Poisoning
Resource Abuse
Tool passed security scan
Supply Chain Compromise
Destructive Action
Context Poisoning
Tool passed security scan
Tool passed security scan
Tool passed security scan
Passed Files (4)Click to expand
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan