PkgRadar

Go modules · proxy.golang.org

github.com/nouchix/pqc-khepra-mcp

Remote Payload: matched "cURL "

Why PkgRadar flagged v1.0.1-0.20260615033247-ec8387492c90

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · github.com/nouchix/[email protected]/pkg/ouroboros/khopesh.go
mediumRemote Payloadmatched "curl " · github.com/nouchix/[email protected]/pkg/phantom/wifi_puck.go
mediumRemote Payloadmatched "cURL " · github.com/nouchix/[email protected]/pkg/sekhem/waf.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.1-0.20260615033247-ec8387492c90High risk412026-06-16
v1.0.0-rc1High risk412026-06-16
v1.0.1-0.20260615031658-63366a336f5eHigh risk412026-06-16
v1.0.0High risk412026-06-16

Block this in CI

PkgRadar gates github.com/nouchix/pqc-khepra-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/nouchix/[email protected]