PkgRadar

npm · registry.npmjs.org

@debian777/kairos-mcp

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 4.8.0-beta.0

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/tools/dump.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/services/id-generator.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/tools/kairos-uri.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/tools/update_schema.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.8.0-beta.0Review152026-06-13
4.7.4Review152026-06-13
4.7.3Review152026-06-12
4.7.2Review152026-06-11
4.7.1Review152026-06-09
4.7.1-rc.2Review152026-06-08
4.7.1-rc.1Review152026-06-05
4.7.1-rc.0Review152026-06-03
4.7.0Review152026-06-02
4.7.0-rc.1Review152026-05-30
4.7.0-rc.0Review152026-05-29
4.6.3Review152026-05-28
4.6.1Review152026-05-28
4.6.2Review152026-05-28
4.6.0-rc.0Review12026-05-27
4.6.0-rc.1Review12026-05-27

Block this in CI

PkgRadar gates @debian777/kairos-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @debian777/[email protected]