PkgRadar

Cargo · crates.io

velaclaw

Webhook Exfil Endpoint, Remote Payload, Messenger Bot Endpoint +1 more

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highWebhook Exfil Endpointvelaclaw-0.3.0/src/onboard/wizard.rs
mediumRemote Payloadvelaclaw-0.3.0/src/agent/loop_.rs
mediumRemote Payloadvelaclaw-0.3.0/src/cron/scheduler.rs
mediumRemote Payloadvelaclaw-0.3.0/src/peripherals/arduino_flash.rs
mediumRemote Payloadvelaclaw-0.3.0/src/peripherals/nucleo_flash.rs
mediumRemote Payloadvelaclaw-0.3.0/src/security/policy.rs
mediumRemote Payloadvelaclaw-0.3.0/src/skills/mod.rs
mediumRemote Payloadvelaclaw-0.3.0/src/tools/cron_add.rs
mediumRemote Payloadvelaclaw-0.3.0/src/tools/cron_update.rs
mediumRemote Payloadvelaclaw-0.3.0/src/tools/schedule.rs

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk842026-06-21

Block this in CI

PkgRadar gates velaclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]