PkgRadar

Go modules · proxy.golang.org

github.com/ai-pivot/xbot

Remote Payload: matched "curl "

Why PkgRadar flagged v0.0.48

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/ai-pivot/[email protected]/channel/cli/cli_debug.go
mediumRemote Payloadmatched "curl " · github.com/ai-pivot/[email protected]/channel/i18n.go
mediumRemote Payloadmatched "cURL " · github.com/ai-pivot/[email protected]/channel/web/web.go
mediumRemote Payloadmatched "cURL " · github.com/ai-pivot/[email protected]/channel/web/web_auth.go
mediumRemote Payloadmatched "cURL " · github.com/ai-pivot/[email protected]/config/config.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.0.48High risk602026-06-15
v0.0.31Review602026-05-31
v0.0.39Review602026-05-31
v0.0.33Review482026-05-31
v0.0.35Review482026-05-31
v0.0.38Review482026-05-31
v0.0.34Review482026-05-31
v0.0.41Review602026-05-31
v0.0.42Review602026-05-31
v0.0.37Review482026-05-31
v0.0.32Review602026-05-31
v0.0.43Review602026-05-31

Block this in CI

PkgRadar gates github.com/ai-pivot/xbot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ai-pivot/[email protected]