PkgRadar

npm · registry.npmjs.org

@agent-native/core

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 0.51.15

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/provider-api/custom-registry.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/integrations/plugin.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/integrations/adapters/telegram.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.51.15High risk282026-06-17
0.51.14High risk282026-06-17
0.51.13High risk282026-06-17
0.51.11High risk282026-06-17
0.51.10High risk282026-06-17
0.51.9High risk282026-06-17
0.51.8High risk282026-06-17
0.51.7High risk282026-06-16
0.51.6High risk282026-06-16
0.51.5High risk282026-06-16
0.51.4High risk282026-06-16
0.51.3High risk282026-06-16
0.51.2High risk282026-06-16
0.51.0High risk282026-06-16
0.51.1High risk282026-06-16
0.50.0High risk282026-06-16
0.49.27High risk282026-06-16
0.49.26High risk282026-06-16
0.49.25High risk282026-06-15
0.49.24High risk282026-06-15
0.49.23High risk282026-06-15
0.49.22High risk282026-06-15
0.49.21High risk282026-06-15
0.49.20High risk282026-06-15
0.49.19High risk282026-06-13
0.49.18High risk282026-06-13
0.49.17High risk282026-06-13
0.49.16High risk282026-06-13
0.49.15High risk282026-06-13
0.49.13High risk282026-06-13
0.49.14High risk282026-06-13
0.49.12High risk282026-06-12
0.49.11High risk282026-06-12
0.49.10High risk282026-06-12
0.49.9High risk282026-06-12
0.49.8High risk282026-06-12
0.49.6High risk282026-06-12
0.49.5High risk282026-06-12
0.49.4High risk282026-06-11
0.49.3High risk282026-06-11
0.49.2High risk282026-06-11
0.49.1High risk282026-06-11
0.49.0High risk282026-06-11
0.48.4High risk282026-06-11
0.48.3High risk282026-06-10
0.48.2High risk282026-06-10
0.47.1High risk282026-06-10
0.46.0Review162026-06-10
0.45.1Review162026-06-10
0.45.0Review162026-06-10
0.44.4Review162026-06-09
0.44.1Review162026-06-09
0.44.3Review162026-06-09
0.44.0Review162026-06-09
0.43.0Review162026-06-09
0.42.0Review162026-06-09
0.41.1Review162026-06-08
0.41.0Review162026-06-08
0.40.2Review162026-06-08
0.40.1Review162026-06-08
0.40.0Review162026-06-07
0.39.2Review162026-06-07
0.39.0Review162026-06-07
0.39.1Review162026-06-07
0.38.0Review162026-06-06
0.37.3Review162026-06-05
0.37.2Review162026-06-05
0.37.0Review162026-06-04
0.37.1Review162026-06-04
0.35.3Review162026-06-03
0.35.2Review162026-06-03
0.35.0Review162026-06-03
0.34.0Review162026-06-03
0.32.18Review142026-06-03
0.32.17Review142026-06-02
0.32.1Review142026-06-01
0.32.2Review142026-06-01
0.32.0Review142026-06-01
0.31.2Review142026-06-01
0.31.1Review142026-06-01
0.31.0Review142026-06-01
0.30.6Review142026-06-01
0.30.5Review142026-05-31
0.30.4Review142026-05-31
0.30.3Review142026-05-31
0.30.2Review142026-05-31
0.29.0Review142026-05-31
0.30.1Review142026-05-31
0.28.5Review142026-05-30
0.28.3Review142026-05-30
0.28.4Review142026-05-30
0.28.2Review142026-05-30
0.28.1Review142026-05-30
0.28.0Review142026-05-30
0.27.0Review142026-05-30
0.26.9Review142026-05-30
0.26.8Review142026-05-30
0.26.7Review142026-05-30
0.26.6Review142026-05-30
0.26.5Review142026-05-30
0.26.3Review142026-05-29
0.26.1Review142026-05-29
0.26.2Review142026-05-29
0.24.9Review162026-05-29
0.24.10Review162026-05-29
0.24.6Review162026-05-29
0.24.7Review162026-05-29
0.24.5Review262026-05-28
0.24.3Review262026-05-28
0.24.4Review262026-05-28
0.23.0Review72026-05-27
0.22.45Review62026-05-26
0.22.43Review1482026-05-24
0.22.44Review1482026-05-24

Block this in CI

PkgRadar gates @agent-native/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agent-native/[email protected]