PkgRadar

npm · registry.npmjs.org

@guilhermefsousa/open-spec-kit

Remote Payload: matched "curl "

Why PkgRadar flagged 1.3.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/templates/agents/skills/integrating-apis/scripts/fill_form.py
mediumRemote Payloadmatched "curl " · package/templates/telemetry/scripts/validate-rules.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.4Review362026-05-25
1.2.26Review982026-05-24
1.3.3Review1002026-05-24

Block this in CI

PkgRadar gates @guilhermefsousa/open-spec-kit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @guilhermefsousa/[email protected]