Web Bro security architecture
Defense-in-depth static analysis, media integrity, scan-context binding and runtime isolation.
currentstatus
Security developers ยท App developers ยท Operatorsaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER
System flow
1
Validate package
2
Analyze media
3
Analyze code + behavior
4
Run available external engines
5
Bind report to exact context
6
Commit only on pass
SCHX / FEATURE LAYER
Source map
- lib/cdn/apps/security/app-security-scanner.ts
- lib/cdn/apps/security/scan-context.ts
- lib/cdn/apps/media-security/app-media-analyzer.ts
- app/api/cdn/apps/security/scan/route.ts
SCHX / FEATURE LAYER
The scanner does not execute submitted application code
Publication analysis is static/structural. It does not run npm install, package lifecycle scripts, app build commands or arbitrary uploaded code.
SCHX / FEATURE LAYER
Built-in analysis
The security report records what engines ran, what they found and whether optional coverage was unavailable or errored.
- Package/path and file identity validation.
- Malware behavior heuristics.
- Secret exposure detection.
- Behavior correlation.
- Network intent analysis.
- Babel AST JavaScript/TypeScript analysis.
- HTML trust-boundary analysis.
- Package supply-chain analysis.
SCHX / FEATURE LAYER
Immutable context binding
A security scan is valid only for the exact package/runtime/media context it analyzed. The final commit re-checks the scan identifiers and deterministic context hashes before storing immutable release bytes.
SCHX / FEATURE LAYER