PkgRadar

Cargo · crates.io

bamboo-engine

Remote Payload: matched "curl "

Why PkgRadar flagged 2026.6.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · bamboo-engine-2026.6.5/src/runtime/runner/tool_execution/output_compressor/scenarios/web_fetch.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.5Review122026-06-05
2026.6.4Review122026-06-04
2026.6.3Review122026-06-03
2026.6.2Review122026-06-02
2026.6.1Review122026-06-01
2026.5.31Review122026-05-31
2026.5.30Review122026-05-30

Block this in CI

PkgRadar gates bamboo-engine (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]