PkgRadar

Go modules · proxy.golang.org

github.com/dever-package/bot

Remote Payload: matched "curl "

Why PkgRadar flagged v0.1.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/dever-package/[email protected]/model/agent/agent_setting.go
mediumRemote Payloadmatched "curl " · github.com/dever-package/[email protected]/service/agent/prompt/skill.go
mediumRemote Payloadmatched "curl " · github.com/dever-package/[email protected]/service/agent/skill/install/command.go
mediumRemote Payloadmatched "curl " · github.com/dever-package/[email protected]/service/agent/skill/install/planner.go
mediumRemote Payloadmatched "curl " · github.com/dever-package/[email protected]/service/agent/tool/curl.go
mediumTls Verification Disabledmatched "--insecure" · github.com/dever-package/[email protected]/service/agent/tool/curl.go
mediumRemote Payloadmatched "cURL " · github.com/dever-package/[email protected]/service/energon/input/value.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.0Review362026-06-20
v0.0.0-20260619014456-9f43d3d9a9f2Review362026-06-20

Block this in CI

PkgRadar gates github.com/dever-package/bot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/dever-package/[email protected]
github.com/dever-package/bot — Go modules security scan | PkgRadar