PkgRadar

npm · registry.npmjs.org

@blundergoat/goat-flow

Remote Payload: matched "curl "

Why PkgRadar flagged 1.11.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/workflow/hooks/deny-dangerous/deny-dangerous-self-test.sh
mediumRemote Payloadmatched "wget " · package/workflow/hooks/deny-dangerous/patterns-shell.sh
mediumCredential file accessmatched ".ssh/" · package/workflow/hooks/deny-dangerous/deny-dangerous-self-test.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.11.0Review652026-06-10
1.10.1Review602026-06-08
1.10.0Review602026-06-07
1.9.1Review652026-06-05
1.9.0Review572026-06-01
1.7.0Review382026-05-30
1.8.0Review452026-05-30

Block this in CI

PkgRadar gates @blundergoat/goat-flow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @blundergoat/[email protected]