Disposable isolated runner
Deep Scan downloads one exact registry artifact, performs static analysis, signs the result and discards the runner. Extension entrypoints and lifecycle code are never launched.
Exact versionStatic onlySigned resultAnalysis boundaries
Published artifacts, installed extensions and private uploads have different boundaries. The product keeps the source, execution policy and analysis limitations visible.
Deep Scan downloads one exact registry artifact, performs static analysis, signs the result and discards the runner. Extension entrypoints and lifecycle code are never launched.
Exact versionStatic onlySigned resultA website cannot enumerate local IDE installations. Local inventory is inspected only by a user-initiated local analysis workflow, and a report leaves the machine only when the user explicitly exports or uploads it.
User initiatedPortable reportPublished-artifact reports are public and shareable. Personal watchlists, scan requests and account data are protected by authenticated row-level access controls.
Public artifactsPrivate workspaceAnalysis guarantees
Instant capability hints never produce a security approval.
Popularity and publisher verification cannot override artifact evidence.
Network, filesystem and process APIs require purpose and evidence context.
A missing required analyzer prevents a complete decision.
Rules, evidence classes, coverage and benchmark limitations are described in the product without overstating external reviewability.