PkgRadar

npm · registry.npmjs.org

@aihubmix/ai-vendor-specs

Credential file access: matched ".aws"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/upstream/anthropic/bedrock/metadata.json
highCredential file accessmatched ".azure" · package/upstream/openai/azure-preview/openapi.json
highCredential file accessmatched ".azure" · package/upstream/openai/azure/openapi.json
highCredential file accessmatched ".aws" · package/upstream/anthropic/bedrock/overlay.yml
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/scripts/build-manifest.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/manifest.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/upstream/cohere/official/metadata.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/upstream/openai/azure-preview/metadata.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/upstream/openai/azure/metadata.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/upstream/vertex/official/metadata.json
mediumRemote Payloadmatched "curl\n " · package/upstream/cohere/official/openapi.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.20260603.0Low risk02026-06-03
0.1.1Low risk02026-06-01
0.1.0Review1242026-05-24

Block this in CI

PkgRadar gates @aihubmix/ai-vendor-specs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aihubmix/[email protected]