PkgRadar

npm · registry.npmjs.org

@hongmaple0820/scale-engine

Remote Payload: matched "curl "

Why PkgRadar flagged 0.40.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/guardrails/advancedDetectors.js
mediumRemote Payloadmatched "Invoke-WebRequest" · package/dist/workflow/gates/GateSystem.js
mediumRemote Payloadmatched "curl " · package/dist/workflow/GovernanceTemplates.js
mediumRemote Payloadmatched "curl " · package/dist/capabilities/InstalledSkillsIntegration.js
mediumRemote Payloadmatched "Invoke-WebRequest" · package/dist/workflow/ReviewAnalyzer.js
mediumRemote Payloadmatched "Invoke-WebRequest" · package/dist/skills/SkillRepository.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.49.0Low risk02026-06-12
0.48.0Low risk02026-06-05
0.47.0Low risk02026-06-04
0.46.0Low risk02026-06-03
0.45.0Low risk02026-06-03
0.44.0Low risk02026-06-02
0.43.0Low risk02026-05-28
0.40.2Review772026-05-25
0.40.1Review1022026-05-24
0.39.0Review1022026-05-24
0.40.0Review1022026-05-24

Block this in CI

PkgRadar gates @hongmaple0820/scale-engine (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hongmaple0820/[email protected]