PkgRadar

npm · registry.npmjs.org

@agenit/cli

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 3.2.3

SeveritySignalEvidence
highCredential file accessmatched "aws_access_key" · package/.flow/tools/pii_scan.py
highCredential file accessmatched "GITHUB_TOKEN" · package/.flow/tools/skill_audit.py
highCredential file accessmatched "aws_access_key" · package/.flow/tools/tests/test_pii_scan.py
highCredential file accessmatched "aws_access_key" · package/config/flow.toml
mediumRemote Payloadmatched "curl " · package/.flow/tools/arduino_tool.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/.flow/tools/marketplace.py
mediumRemote Payloadmatched "curl " · package/.flow/tools/skill_audit.py
mediumRemote Payloadmatched "curl " · package/.flow/hooks/tests/test_before_squad_dispatch.py
mediumRemote Payloadmatched "curl " · package/.flow/tools/tests/test_skill_audit.py
mediumRemote Payloadmatched "curl " · package/.flow/hooks/tests/test_slopsquatting.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/config/flow.toml
mediumLarge Javascript Payload18615395 bytes · package/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.2.3Review1262026-05-25
4.0.1-beta.1Review402026-05-25

Related campaigns

Block this in CI

PkgRadar gates @agenit/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agenit/[email protected]