PkgRadar

npm · registry.npmjs.org

@genaiscript/core

Remote Dependency Spec: optionalDependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgz"

Why PkgRadar flagged 2.4.1

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgz" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/browser/githubclient.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/esm/githubclient.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.4.1High risk412026-06-10
2.5.0High risk512026-06-10
2.5.1High risk512026-06-10
2.4.0High risk412026-06-10

Block this in CI

PkgRadar gates @genaiscript/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @genaiscript/[email protected]