PkgRadar

Cargo · crates.io

agent-code-lib

Remote Payload: matched "curl "

Why PkgRadar flagged 0.22.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · agent-code-lib-0.22.1/src/skills/mod.rs
mediumRemote Payloadmatched "curl " · agent-code-lib-0.22.1/src/tools/bash/read_only_validation.rs
mediumRemote Payloadmatched "curl " · agent-code-lib-0.22.1/src/tools/bash_parse.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.22.1High risk612026-06-01

Block this in CI

PkgRadar gates agent-code-lib (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]