Cargo · crates.io
jarvy
Remote Payload: matched "curl "
Why PkgRadar flagged 0.1.1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/git/setup.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/mcp/prompts.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/mcp/tools.rs |
| medium | Remote Payload | matched "raw.githubusercontent.com" · jarvy-0.1.1/src/remote.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/setup.rs |
| medium | Remote Payload | matched "raw.githubusercontent.com" · jarvy-0.1.1/src/team/inheritance.rs |
| medium | Remote Payload | matched "raw.githubusercontent.com" · jarvy-0.1.1/src/tools/brew/definition.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/tools/nvm/definition.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/tools/pinned_installer.rs |
| medium | Remote Payload | matched "curl " · jarvy-0.1.1/src/tools/rust/definition.rs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.1 | High risk | 106 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem cargo [email protected]