PkgRadar

Cargo · crates.io

vtcode-core

Remote Payload: matched "invoke-webrequest"

Why PkgRadar flagged 0.121.1

SeveritySignalEvidence
mediumRemote Payloadmatched "invoke-webrequest" · vtcode-core-0.121.1/src/command_safety/windows_cmdlet_db.rs
mediumRemote Payloadmatched "curl " · vtcode-core-0.121.1/src/pods/manager.rs
mediumRemote Payloadmatched "curl " · vtcode-core-0.121.1/src/sandboxing/debug.rs
mediumRemote Payloadmatched "curl " · vtcode-core-0.121.1/src/skills/templates.rs
mediumRemote Payloadmatched "curl " · vtcode-core-0.121.1/src/terminal_setup/features/shell_integration.rs
mediumRemote Payloadmatched "curl " · vtcode-core-0.121.1/src/terminal_setup/terminals/iterm2.rs
mediumRemote Payloadmatched "wget " · vtcode-core-0.121.1/src/tools/validation/commands.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.121.1High risk622026-06-03
0.121.0High risk622026-06-03
0.120.0High risk622026-06-03
0.119.0High risk622026-06-03
0.118.0High risk622026-06-03
0.117.7High risk622026-06-03
0.117.6High risk622026-06-03
0.117.5High risk622026-06-02
0.117.4High risk622026-06-02
0.117.3High risk622026-06-02
0.117.2High risk622026-06-02
0.117.1High risk622026-06-01
0.117.0High risk622026-06-01
0.116.4High risk622026-05-31
0.116.3High risk622026-05-31
0.116.2Review622026-05-31
0.116.1Review622026-05-31
0.116.0Review622026-05-30
0.114.0High risk622026-05-30
0.113.0High risk622026-05-30
0.112.0High risk622026-05-30
0.111.1High risk622026-05-30
0.108.4High risk622026-05-30
0.115.0Review622026-05-30

Block this in CI

PkgRadar gates vtcode-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]