PkgRadar

Cargo · crates.io

aidaemon

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/agent/loop/loop_utils.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/agent/runtime/system_prompt.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/core.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/mcp/mod.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/tools/channel_history.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/tools/command_patterns.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/tools/command_semantics.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · aidaemon-0.10.0/src/tools/manage_skills.rs
mediumRemote Payloadmatched "curl " · aidaemon-0.10.0/src/tools/run_command.rs
mediumCredential file accessmatched ".ssh/" · aidaemon-0.10.0/src/tools/write_file.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.0High risk1122026-06-05

Block this in CI

PkgRadar gates aidaemon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]