PkgRadar

npm · registry.npmjs.org

@clawpump/claw-agent

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 0.1.1

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/bin/cli.mjs
highCredential file accessmatched ".npmrc" · package/agent/hermes_cli/security_advisories.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/agent/apps/desktop/electron/bootstrap-runner.cjs
mediumRemote Payloadmatched "curl " · package/agent/plugins/memory/hindsight/__init__.py
mediumRemote Payloadmatched "curl " · package/agent/hermes_cli/memory_setup.py
mediumRemote Payloadmatched "github.com/KittenML/KittenTTS/releases/download" · package/agent/hermes_cli/setup.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · package/agent/hermes_cli/model_switch.py
mediumCredential file accessmatched ".npmrc" · package/agent/tools/skills_guard.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.1Review1932026-06-04
0.1.0Review1932026-06-03

Block this in CI

PkgRadar gates @clawpump/claw-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @clawpump/[email protected]