PkgRadar

npm · registry.npmjs.org

@hallucination-studio/harness-engine

Suspicious Publish Context: {"package_age_days":2,"publisher":"flamingo.o","burst_same_day":1,"burst_week":1,"lure":null,"version_anomaly":false,"new_account":true}

Why PkgRadar flagged 1.0.0-nightly.20260613.2

SeveritySignalEvidence
mediumSuspicious Publish Context{"package_age_days":2,"publisher":"flamingo.o","burst_same_day":1,"burst_week":1,"lure":null,"version_anomaly":false,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-nightly.20260613.2Review102026-06-13
1.0.1Low risk02026-06-12
1.0.0-beta.18.ab4b55aLow risk02026-06-12
1.0.0-nightly.20260612.1Low risk02026-06-12
1.0.0-beta.17.412ec6eLow risk02026-06-12
1.0.0-beta.16.565063cLow risk02026-06-12
1.0.0-beta.15.f39cb72Low risk02026-06-12
1.0.0-beta.14.a797755Low risk02026-06-12
1.0.0-beta.13.cf40fabLow risk02026-06-11
1.0.0-beta.12.d308768Low risk02026-06-11
1.0.0-beta.11.2a4849aLow risk02026-06-11
1.0.0-beta.10.9ff10d9Low risk02026-06-11
1.0.0-beta.9.bb2cd30Low risk02026-06-11
1.0.0-beta.8.87407Low risk02026-06-11
1.0.0Low risk02026-06-11

Block this in CI

PkgRadar gates @hallucination-studio/harness-engine (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hallucination-studio/[email protected]