PkgRadar

npm · registry.npmjs.org

@evalops/maestro

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 0.10.48

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/safety/credential-patterns.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/memory/team-memory-secret-scan.js
highCredential file accessmatched "AWS_ACCESS_KEY" · package/dist/oauth/command-key.js
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('node:fs');const cp=require('node:child_process');if(!fs.existsSync('./scripts/ensure-deps.js')||!fs.existsSync('./packages/contracts/package.json'))process.exit(0);const r=cp.spawnSync(process.execPath,['./scripts/ensure-deps.js','--no-install'],{stdio:'inherit'});process.exit(r.status??1);\"" · package.json
mediumCredential file accessmatched "AWS_ACCESS_KEY" · package/dist/agent/providers/google.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.48Review452026-05-30
0.10.47Review482026-05-29
0.10.45Review482026-05-28
0.10.46Review482026-05-28
0.10.44Review512026-05-28
0.10.43Review512026-05-28
0.10.41Review512026-05-28
0.10.42Review512026-05-28
0.10.39Review432026-05-27
0.10.40Review432026-05-27
0.10.38Review432026-05-27
0.10.36Review432026-05-27
0.10.37Review432026-05-27
0.10.31Review432026-05-26
0.10.30Review432026-05-26
0.10.29Review432026-05-26
0.10.28Review432026-05-26
0.10.26Review432026-05-25
0.10.25Review432026-05-25
0.10.23Review1452026-05-25
0.10.24Review1452026-05-25

Block this in CI

PkgRadar gates @evalops/maestro (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @evalops/[email protected]