PkgRadar

Go modules · proxy.golang.org

github.com/fayzkk889/mcpsense

Credential file access: matched "id_rsa"

Why PkgRadar flagged v0.3.1-0.20260606195845-9b7f8fc0ac9a

SeveritySignalEvidence
highCredential file accessmatched "id_rsa" · github.com/fayzkk889/[email protected]/internal/checks/tool_poisoning.go
mediumRemote Payloadmatched "wget " · github.com/fayzkk889/[email protected]/internal/checks/config_security.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/fayzkk889/[email protected]/internal/report/sarif.go
mediumRemote Payloadmatched "cURL " · github.com/fayzkk889/[email protected]/internal/scanner/live.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.3.1-0.20260606195845-9b7f8fc0ac9aHigh risk712026-06-07
v0.3.0High risk712026-06-07

Block this in CI

PkgRadar gates github.com/fayzkk889/mcpsense (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/fayzkk889/[email protected]