37OUT OF 100
High riskDangerousStatic read
npm/bufferutil
bufferutil is a widely used, long-standing utility package for WebSocket performance. The flagged install-time activity is a standard build process for native Node.js modules (node-gyp-build), which is fully consistent with the package's documented purpose and industry standards. No malicious behavior was observed in our static read; full runtime behavior was not executed in a sandbox on this pass.
Repository size
0 KBPackages
1Stars
—
Created
2015-01-29
Reputation signals
bufferutil
npm package
Code & behavior signals
Native build hook
LowBehavior
The package uses an install script (node-gyp-build) to compile native C++ code. This is expected behavior for this package and is consistent with its declared intent.
End-to-end logs
Clone
›Fetched npm package bufferutil@4.1.0
›Verified tarball integrity via sha512
Static scan
›Detected install hook: node-gyp-build
›No obfuscation or unauthorized network activity found
Read
›README confirms native module usage for WebSocket performance
›Install hook matches documented build requirements
Score
›Score computed by formula: 37/100 (deterministic, code-driven)
›-40 [code] install_time_network: Network/shell activity wired into an install-time hook (runs on install, before import).
›-8 [code] install_hook: A pre/post-install script is present (the surface install-time attacks hide in).
›-3 [code] model_findings: 1 code/behavior finding(s) reported by the read model.
›-6 [code] escalation_pending: Escalated to the dynamic sandbox; not yet cleared by a runtime observation.
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+4 [reputation] good_sentiment: Positive community sentiment (100/100).
Escalation
›Escalation gate tripped on the static read
›Reason: install-time network/shell activity detected on static read
›Escalated to a deep behavioural read
Deep read
›The package bufferutil is a standard WebSocket utility library that uses a native addon. During installation, it runs 'node-gyp-build' to locate or compile the native binary required for its operations. This is standard behavior for Node.js packages with native C/C++ components.
›[build_step/low] Runs node-gyp-build during installation to compile or load native C/C++ addons. — evidence: package.json (scripts.install)
›Read-only analysis: the code was NOT executed, so run-time-fetched payloads and run-time-built endpoints were not observed.
Auto-published at clauderabbit.in/npm/bufferutil · re-checked when the package changes