The AI review rates the findings as likely false positive, but the risk score (72/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v2.6.0
- Artifact
- SHA256 458…F44
- Source
- Findings (non-IoC)
Is @raycast/api safe?
This package is the official Raycast API SDK, used by developers to build extensions for the Raycast productivity launcher. It declares no special permissions or network endpoints in the bundle metadata, but the code itself makes standard HTTP and WebSocket calls to Raycast and GitHub APIs to handle authentication, publish extensions, and fetch user profiles.
The scanner flagged a few items that look suspicious at first glance. Two files in the dist directory triggered the YARA--supply_chain_sourcemap_appended_iife finding because they have source maps appended to the end, which is a normal build artifact. An obfuscation rule tripped on the TypeScript declaration file types/index.d.ts with the OBFUSCATION-INVISIBLE_TAGS_BLOCK finding due to invisible tag characters, which is a known false positive for type definitions. Several network rules flagged standard API calls in files like dist/api/raycast.js.
None of these findings represent actual malicious behavior. There are no hidden instructions aimed at AI agents, no attempts to read sensitive files like SSH keys or AWS credentials, and no network calls to unknown domains. The flagged items are entirely the result of standard JavaScript build processes and TypeScript type definitions triggering overly broad scanner rules. The package is safe to use for its intended purpose.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 2 | dist/utils/publish/publish-to-store.jsdist/commands/publish/index.js | - |
Finding Categories
YARA Rules Matched
1 rule(2 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The package @raycast/api is the official SDK for building Raycast extensions. The scanner flagged three categories of findings, all of which are false positives stemming from standard build artifacts, expected API interactions, and type definitions.
Two YARA--supply_chain_sourcemap_appended_iife findings appear in dist/utils/publish/publish-to-store.js and dist/commands/publish/index.js. This rule triggers when a bundled JavaScript file has a source map appended to the end of the file. This is a standard build artifact for TypeScript projects using bundlers like esbuild, rollup, or webpack. It does not indicate a supply chain compromise, nor does it represent malicious payload injection. The presence of a source map simply allows developers to debug the minified output.
The scanner also flagged multiple network operations (NET-SOCKET_IO, NET-FETCH, NET-JQUERY_AJAX) across files like dist/api/raycast.js, dist/api/github.js, and dist/commands/login/index.js. These are expected network calls for an SDK that interacts with the Raycast API, GitHub API, and handles user authentication. There are no calls to unknown or suspicious external domains. Furthermore, the code does not contain credential-exfiltration patterns targeting sensitive paths like .ssh, .aws, or .kube. The network activity is strictly confined to the documented APIs the SDK is designed to wrap.
An OBFUSCATION-INVISIBLE_TAGS_BLOCK finding appears in types/index.d.ts. TypeScript declaration files frequently contain specific Unicode characters or formatting that trigger invisible tag block rules. This is a well-documented false positive for type definition files and does not represent steganography, hidden instructions, or obfuscated code.
Additionally, there are zero tool-poisoning findings. The SDK does not define or orchestrate MCP tools, so there is no risk of hidden AI directives manipulating agent behavior. The package operates strictly as a development library and CLI utility for the Raycast ecosystem.
The strongest counterargument is that the YARA--supply_chain_sourcemap_appended_iife rule explicitly references supply chain attacks, which might imply malicious tampering with the build output. However, the rule simply detects the structural presence of an appended source map in an IIFE bundle. This is a completely normal characteristic of published npm packages. Combined with the total absence of tool-poisoning directives, credential harvesting, or suspicious network destinations, the evidence points entirely to scanner noise.
Key Reasons
- Zero tool-poisoning findings and no hidden AI directives
- No credential-exfiltration patterns targeting sensitive paths like .ssh or .aws
- Network calls are strictly confined to documented Raycast and GitHub APIs
- YARA supply chain rule triggered by standard appended source maps in dist files
- Obfuscation rule triggered by known false positive in TypeScript declaration files
False Positive Considerations
- YARA--supply_chain_sourcemap_appended_iife matching standard appended source maps in bundled JS
- OBFUSCATION-INVISIBLE_TAGS_BLOCK matching Unicode formatting in TypeScript declaration files
- NET-SOCKET_IO and NET-FETCH rules matching expected API calls to Raycast and GitHub endpoints
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
n8n version history
Risk trend by version
18 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace