PkgRadar

Go modules · proxy.golang.org

github.com/agent-hellboy/mcp-runtime

Remote Payload: matched "github.com/cert-manager/cert-manager/releases/download"

Why PkgRadar flagged v0.1.1-0.20260601102405-33321e63b047

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/cert-manager/cert-manager/releases/download" · github.com/agent-hellboy/[email protected]/internal/cli/certmanager/letsencrypt.go
mediumRemote Payloadmatched "curl " · github.com/agent-hellboy/[email protected]/internal/cli/cluster/doctor/doctor.go
mediumRemote Payloadmatched "curl " · github.com/agent-hellboy/[email protected]/internal/cli/cluster/doctor/managed_team.go
mediumRemote Payloadmatched "cURL " · github.com/agent-hellboy/[email protected]/internal/operator/controller.go
mediumRemote Payloadmatched "curl " · github.com/agent-hellboy/[email protected]/pkg/registrypush/push.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.1-0.20260601102405-33321e63b047High risk602026-06-02
v0.1.0High risk602026-06-02
v0.0.0-20260530154953-fae92be805d8High risk602026-05-31
v0.0.0-20260530144022-ef014d97d1bbHigh risk602026-05-31
v0.0.0-20260530095546-20a082ee674dHigh risk602026-05-31
v0.0.0-20260526115552-2d3e498552bbHigh risk602026-05-30

Block this in CI

PkgRadar gates github.com/agent-hellboy/mcp-runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/agent-hellboy/[email protected]