PkgRadar

npm · registry.npmjs.org

@convo-lang/convo-lang-mcp-client

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 0.9.6

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/src/lib/McpOAuthClientProvider.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.6High risk402026-06-10
0.9.7High risk402026-06-10

Block this in CI

PkgRadar gates @convo-lang/convo-lang-mcp-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @convo-lang/[email protected]