Go modules · proxy.golang.org
github.com/vbonnet/dear-agent
Go Generate Shell: //go:generate directive shells out to curl/wget/bash — runs during `go generate`.
Why PkgRadar flagged v0.0.0-20260611003259-edcb4bb0c5de
| Severity | Signal | Evidence |
|---|---|---|
| medium | Go Generate Shell | //go:generate directive shells out to curl/wget/bash — runs during `go generate`. · github.com/vbonnet/[email protected]/engram/hooks-bin/internal/validator/doc.go |
| medium | Remote Payload | matched "curl " · github.com/vbonnet/[email protected]/agm/cmd/agm/new_currenttmux.go |
| medium | Remote Payload | matched "curl " · github.com/vbonnet/[email protected]/agm/cmd/agm/new_harness.go |
| medium | Remote Payload | matched "wget " · github.com/vbonnet/[email protected]/agm/internal/session/session.go |
| medium | Remote Payload | matched "github.com/perplexityai/bumblebee/releases/download" · github.com/vbonnet/[email protected]/cmd/dear-agent-bumblebee/install.go |
| medium | Credential file access | matched ".config/gcloud" · github.com/vbonnet/[email protected]/agm/cmd/agm/search.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20260611003259-edcb4bb0c5de | High risk | 91 | 2026-06-12 |
Block this in CI
pkgradar gate --ecosystem go github.com/vbonnet/[email protected]