PkgRadar

Composer · packagist.org

forgeomni/superagent

Remote Payload: matched "curl "

Why PkgRadar flagged v1.1.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/src/Agent/BuiltinAgents/VerificationAgent.php
mediumRemote Payloadmatched "cURL " · ForgeOmni-SuperAgent-41dff4d/src/CLI/SuperAgentApplication.php
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/src/Skills/BuiltinSkills/BatchSkill.php
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/tests/Unit/AgentToolProductivityTest.php
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/tests/Unit/Guardrails/PromptInjectionDetectorTest.php
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/tests/Unit/Harness/WireProjectingPermissionCallbackTest.php
mediumRemote Payloadmatched "curl " · ForgeOmni-SuperAgent-41dff4d/tests/Unit/Phase3PermissionsTest.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.1.1High risk972026-06-04
v1.1.0High risk972026-06-02
v1.0.10High risk972026-05-31
v1.0.8High risk972026-05-30

Block this in CI

PkgRadar gates forgeomni/superagent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer forgeomni/[email protected]