PkgRadar

Go modules · proxy.golang.org

github.com/vybzai/clipbeam-cli

Credential file access: matched ".ssh/"

Why PkgRadar flagged v0.1.1

SeveritySignalEvidence
highCredential file accessmatched ".ssh/" · github.com/vybzai/[email protected]/cmd/clipbeam/cli/skillgen.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/vybzai/[email protected]/cmd/clipbeam/cli/verbs_setup_release.go
mediumRemote Payloadmatched "github.com/vybzai/clipbeam-cli/releases/download" · github.com/vybzai/[email protected]/cmd/clipbeam/cli/verbs_setup_tarball.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.1High risk542026-06-04
v0.1.0High risk302026-06-04
v0.1.2High risk542026-06-04

Block this in CI

PkgRadar gates github.com/vybzai/clipbeam-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/vybzai/[email protected]