PkgRadar

npm · registry.npmjs.org

@dypai-ai/mcp

Remote Payload: matched "curl "

Why PkgRadar flagged 1.5.30

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/src/tools/enrich.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.19Low risk02026-06-11
1.6.18Low risk02026-06-08
1.6.17Low risk02026-06-08
1.6.16Low risk02026-06-07
1.6.15Low risk02026-06-07
1.6.14Low risk02026-06-07
1.6.13Low risk02026-06-07
1.6.12Low risk02026-05-29
1.6.10Low risk02026-05-28
1.6.11Low risk02026-05-28
1.6.6Low risk02026-05-27
1.6.7Low risk02026-05-27
1.6.0Low risk02026-05-27
1.5.34Low risk02026-05-26
1.5.35Low risk02026-05-26
1.5.33Low risk02026-05-25
1.5.32Low risk02026-05-25
1.5.31Low risk02026-05-25
1.5.30Review122026-05-24
1.5.29Review122026-05-24
1.5.28Review122026-05-24
1.5.27Review122026-05-24
1.5.26Review122026-05-24
1.5.25Review122026-05-24
1.5.24Review122026-05-24

Block this in CI

PkgRadar gates @dypai-ai/mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dypai-ai/[email protected]