PkgRadar

Cargo · crates.io

torc

Credential File Packaged: torc-0.34.0/.env

Why PkgRadar flagged 0.34.0

SeveritySignalEvidence
highCredential File Packagedtorc-0.34.0/.env · torc-0.34.0/.env
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · torc-0.34.0/build.rs
mediumRemote Payloadmatched "curl " · torc-0.34.0/src/cli.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · torc-0.34.0/src/mcp_server/tools.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.34.0High risk892026-06-03
0.33.3High risk892026-05-30

Block this in CI

PkgRadar gates torc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]