PkgRadar

npm · registry.npmjs.org

@agentstep/agent-sdk

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.5.67

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/chunk-E744ZIBI.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/chunk-VGCH4BVG.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.67Review242026-06-02
0.5.68Review162026-06-02
0.5.64Review242026-06-02
0.5.65Review162026-06-02
0.5.63Review162026-06-01
0.5.61Review162026-06-01
0.5.62Review162026-06-01
0.5.60Review242026-06-01
0.5.58Review242026-06-01
0.5.59Review242026-06-01
0.5.57Review162026-05-31
0.5.56Review162026-05-31
0.5.55Review162026-05-31
0.5.54Review162026-05-31
0.5.53Review162026-05-31
0.5.52Review162026-05-31
0.5.51Review162026-05-31
0.5.50Review162026-05-31
0.5.49Review162026-05-31
0.5.48Review162026-05-31
0.5.47Review162026-05-31
0.5.46Review162026-05-31
0.5.41Review232026-05-27
0.5.42Review232026-05-27
0.5.40Review232026-05-27
0.5.38Review232026-05-25
0.5.39Review232026-05-25
0.5.36Review232026-05-25
0.5.35Review962026-05-24
0.5.34Review962026-05-24
0.5.33Review962026-05-24
0.5.28Review962026-05-24
0.5.27Review962026-05-24
0.5.26Review962026-05-24
0.5.25Review962026-05-24
0.5.23Review962026-05-24
0.5.24Review962026-05-24

Block this in CI

PkgRadar gates @agentstep/agent-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agentstep/[email protected]