PkgRadar

npm · registry.npmjs.org

@inspectr/mcplab

Credential file access: matched ".AZURE"

Why PkgRadar flagged 1.15.0

SeveritySignalEvidence
highCredential file accessmatched ".AZURE" · package/dist/app-server/provider-models.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/app/assets/index-C2W0NrXX.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.21.1Low risk02026-06-12
1.21.0Low risk02026-06-12
1.20.1Low risk02026-06-04
1.20.2Low risk02026-06-04
1.20.0Low risk02026-06-04
1.19.0Low risk02026-05-28
1.18.0Low risk02026-05-28
1.17.0Low risk02026-05-27
1.15.0Review302026-05-24
1.16.0Review302026-05-24

Related campaigns

Block this in CI

PkgRadar gates @inspectr/mcplab (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @inspectr/[email protected]