PkgRadar

Go modules · proxy.golang.org

github.com/nextlevelbuilder/goclaw

Remote Payload: matched "curl "

Why PkgRadar flagged v1.76.2-0.20260603144224-d85bf17171fd

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/nextlevelbuilder/[email protected]/internal/skills/guard.go
mediumRemote Payloadmatched "curl " · github.com/nextlevelbuilder/[email protected]/internal/store/sqlitestore/schema.go
mediumRemote Payloadmatched "cURL " · github.com/nextlevelbuilder/[email protected]/internal/tools/scrub_server.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.76.2-0.20260603144224-d85bf17171fdHigh risk602026-06-12
v1.76.2-0.20260409172151-6a34b7ec65e4High risk412026-06-12

Block this in CI

PkgRadar gates github.com/nextlevelbuilder/goclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/nextlevelbuilder/[email protected]