PkgRadar

npm · registry.npmjs.org

@hanna84/mcp-writing

Credential file access: matched ".ssh"

Why PkgRadar flagged 3.20.0

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/src/scripts/setup-openclaw-env.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.29.3Low risk02026-06-11
3.29.2Low risk02026-06-11
3.29.1Low risk02026-06-07
3.29.0Low risk02026-06-07
3.28.0Low risk02026-06-07
3.26.0Low risk02026-06-06
3.27.0Low risk02026-06-06
3.25.0Low risk02026-06-06
3.24.1Low risk02026-06-06
3.24.0Low risk02026-06-06
3.23.2Low risk02026-06-06
3.23.1Low risk02026-05-30
3.23.0Low risk02026-05-30
3.22.5Low risk02026-05-30
3.22.4Low risk02026-05-29
3.22.2Low risk02026-05-28
3.22.3Low risk02026-05-28
3.20.0Review302026-05-24
3.19.0Review302026-05-24
3.18.1Review302026-05-24

Related campaigns

Block this in CI

PkgRadar gates @hanna84/mcp-writing (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hanna84/[email protected]