PkgRadar

npm · registry.npmjs.org

@caoscompanybr/merlin

Remote Payload

Why PkgRadar flagged 3.5.0

SeveritySignalEvidence
mediumRemote Payloadpackage/.merlin-core/core/execution/env-preflight.js
mediumRemote Payloadpackage/.merlin-core/tools/vps-security-audit.sh

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
3.5.0Review242026-06-21

Block this in CI

PkgRadar gates @caoscompanybr/merlin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @caoscompanybr/[email protected]
@caoscompanybr/merlin — npm security scan | PkgRadar