PkgRadar

Cargo · crates.io

llman

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.0.41

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · llman-0.0.41/src/config_schema.rs
mediumRemote Payloadmatched "curl " · llman-0.0.41/src/x/claude_code/config.rs
mediumRemote Payloadmatched "curl " · llman-0.0.41/src/x/claude_code/security.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · llman-0.0.41/src/x/sdd_eval/playbook.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.41High risk262026-06-05

Block this in CI

PkgRadar gates llman (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]