PkgRadar

npm · registry.npmjs.org

@cgh567/agent

Shipped Live Secret, Remote Payload, Credential file access +1 more

Why PkgRadar flagged 2.4.1

SeveritySignalEvidence
highShipped Live Secretpackage/extensions/email/commands/slack-setup.ts
mediumRemote Payloadpackage/lib/graph/analytics/benchmark-scientific.js
mediumRemote Payloadpackage/lib/graph/misc/ensure-ollama.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.4.1High risk1052026-06-25
2.4.0High risk1052026-06-25

Related campaigns

Block this in CI

PkgRadar gates @cgh567/agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cgh567/[email protected]