PkgRadar

npm · registry.npmjs.org

@coralai/sps-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 0.55.13

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/core/config.js
mediumRemote Payloadmatched "curl " · package/dist/commands/doctor.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.55.13Review162026-06-12
0.55.12Review242026-06-12
0.55.11Review242026-06-12
0.55.10Review242026-06-11
0.55.6Review242026-06-08
0.55.5Review242026-06-06
0.55.4Review242026-06-06
0.55.3Review242026-06-06
0.55.2Review242026-06-06
0.55.1Review242026-06-06
0.55.0Review242026-06-06
0.54.4Review242026-06-06
0.54.2Review242026-06-04
0.54.3Review242026-06-04
0.54.1Review242026-06-04
0.54.0Review242026-06-04
0.53.4Review242026-06-04
0.53.2Review242026-06-03
0.53.3Review242026-06-03

Block this in CI

PkgRadar gates @coralai/sps-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @coralai/[email protected]