PkgRadar

npm · registry.npmjs.org

@coze-arch/cli

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 0.0.27

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/expo/pnpm-lock.yaml
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/nextjs/pnpm-lock.yaml
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/nuxt-vue/pnpm-lock.yaml
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/pi-agent/pnpm-lock.yaml
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/taro/pnpm-lock.yaml
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/__templates__/vite/pnpm-lock.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.27Review402026-05-26
0.0.26-alpha.f165eeReview402026-05-26
0.0.25Review582026-05-25
0.0.26Review582026-05-25

Block this in CI

PkgRadar gates @coze-arch/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @coze-arch/[email protected]