PkgRadar

Go modules · proxy.golang.org

github.com/backendstack21/kode

Remote Payload: matched "curl "

Why PkgRadar flagged v1.8.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/backendstack21/[email protected]/cmd/odek/transcribe_tool.go
mediumRemote Payloadmatched "curl " · github.com/backendstack21/[email protected]/cmd/odek/vision_tool.go
mediumRemote Payloadmatched "invoke-webrequest" · github.com/backendstack21/[email protected]/internal/memory/scan.go
mediumRemote Payloadmatched "curl " · github.com/backendstack21/[email protected]/internal/skills/importer.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.8.0High risk532026-06-15
v1.2.0High risk412026-06-12
v1.4.0High risk532026-06-12
v1.6.0High risk532026-06-12
v1.3.0High risk532026-06-12
v1.0.0Review292026-05-31

Block this in CI

PkgRadar gates github.com/backendstack21/kode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/backendstack21/[email protected]