PkgRadar

Go modules · proxy.golang.org

github.com/chetto1983/aura

Reverse Shell, Credential file access, Obfuscation Density

Why PkgRadar flagged v1.0.2-0.20260621135723-c3f408dba41d

SeveritySignalEvidence
highReverse Shellgithub.com/chetto1983/[email protected]/cmd/aura/mcp.go

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.2-0.20260621135723-c3f408dba41dHigh risk432026-06-22
v0.3.0Low risk02026-06-22
v1.0.0High risk432026-06-22
v0.3.1Low risk02026-06-22
v0.1.0High risk432026-06-22
v0.2.0Review122026-06-22
v0.1.1High risk432026-06-22
v1.0.2-0.20260621110224-a7bf6d18c43eHigh risk432026-06-22
v0.3.2Low risk02026-06-22
v1.0.1High risk432026-06-22

Block this in CI

PkgRadar gates github.com/chetto1983/aura (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/chetto1983/[email protected]