PkgRadar

npm · registry.npmjs.org

@fro.bot/systematic

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 2.23.6

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index-175fc4yn.js
mediumRemote Payloadmatched "curl " · package/skills/rclone/scripts/check_setup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.32.0Low risk02026-06-15
2.31.1Low risk02026-06-14
2.31.0Low risk02026-06-07
2.30.1Low risk02026-06-07
2.30.0Low risk02026-06-07
2.29.0Low risk02026-06-07
2.28.0Low risk02026-06-05
2.27.0Low risk02026-06-05
2.26.0Low risk02026-06-05
2.25.0Low risk02026-06-05
2.23.6Review162026-05-27
2.24.0Review162026-05-27
2.23.4Review162026-05-27
2.23.5Review162026-05-27

Block this in CI

PkgRadar gates @fro.bot/systematic (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @fro.bot/[email protected]
@fro.bot/systematic — npm security scan | PkgRadar