PkgRadar

npm · registry.npmjs.org

@elisym/cli

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 0.21.2

SeveritySignalEvidence
mediumCredential file accessmatched "GITHUB_TOKEN" · package/skills-examples/github-repo/scripts/github_repo.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.22.5Low risk02026-06-02
0.22.4Low risk02026-06-01
0.22.3Low risk02026-06-01
0.22.1Low risk02026-05-31
0.22.0Low risk02026-05-31
0.21.3Low risk02026-05-30
0.21.2Review32026-05-27
0.21.1Review32026-05-27
0.21.0Review32026-05-26
0.19.0Review422026-05-24
0.20.0Review422026-05-24

Block this in CI

PkgRadar gates @elisym/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @elisym/[email protected]