PkgRadar

Cargo · crates.io

kumiho-construct

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 2026.5.20

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · kumiho-construct-2026.5.20/src/onboard/wizard.rs
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · kumiho-construct-2026.5.20/build.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/agent/loop_.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/cron/mod.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/cron/scheduler.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/peripherals/arduino_flash.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/peripherals/nucleo_flash.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/security/policy.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/skills/audit.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/skills/mod.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/tools/cron_add.rs
mediumRemote Payloadmatched "curl " · kumiho-construct-2026.5.20/src/tools/cron_update.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.5.20High risk1502026-06-01

Block this in CI

PkgRadar gates kumiho-construct (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
kumiho-construct — Cargo security scan | PkgRadar