PkgRadar

npm · registry.npmjs.org

@elizaos/plugin-local-embedding

Remote Dependency Spec: dependencies.node-llama-cpp="github:milady-ai/node-llama-cpp#v3.18.1-milady.3"

Why PkgRadar flagged 2.0.0-beta.1

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.node-llama-cpp="github:milady-ai/node-llama-cpp#v3.18.1-milady.3" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.node-llama-cpp changed to remote spec in 2.0.0-beta.1 vs 2.0.0-alpha.537: "github:milady-ai/node-llama-cpp#v3.18.1-milady.3" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-alpha.11Low risk02026-06-16
2.0.0-alpha.12Low risk02026-06-16
2.0.0-alpha.3Low risk02026-06-16
2.0.0-alpha.537Low risk02026-06-16
2.0.0-beta.1Review242026-06-16

Block this in CI

PkgRadar gates @elizaos/plugin-local-embedding (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @elizaos/[email protected]