PkgRadar

npm · registry.npmjs.org

@lightcone-ai/daemon

Known Indicator Filename: package/src/_vendor/browser/playbooks/execution.js

Why PkgRadar flagged 0.23.50

SeveritySignalEvidence
highKnown Indicator Filenamepackage/src/_vendor/browser/playbooks/execution.js · package/src/_vendor/browser/playbooks/execution.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/mcp-servers/mysql/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/mcp-servers/portfolio-analysis/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/mcp-servers/portfolio-read/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/mcp-servers/publisher/package-lock.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.23.71Low risk02026-06-06
0.23.70Low risk02026-06-02
0.23.69Low risk02026-06-01
0.23.68Low risk02026-05-30
0.23.67Low risk02026-05-30
0.23.65Low risk02026-05-30
0.23.66Low risk02026-05-30
0.23.62Low risk02026-05-30
0.23.61Low risk02026-05-30
0.23.60Low risk02026-05-30
0.23.55Low risk02026-05-30
0.23.54Low risk02026-05-30
0.23.53Low risk02026-05-30
0.23.50Review932026-05-25
0.23.51Review932026-05-25
0.23.49Review452026-05-24
0.23.48Review452026-05-24
0.23.47Review452026-05-24
0.23.46Low risk02026-05-24

Block this in CI

PkgRadar gates @lightcone-ai/daemon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lightcone-ai/[email protected]