PkgRadar

npm · registry.npmjs.org

@lizard-build/cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.3.65

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/commands/add.js
mediumRemote Payloadmatched "curl " · package/install.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/commands/add.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.65Review102026-06-16
0.3.64Review102026-06-16
0.3.63Review102026-06-16
0.3.62Review102026-06-16
0.3.61Review102026-06-16
0.3.60Review102026-06-15
0.3.59Review102026-06-15
0.3.58Review102026-06-15
0.3.57Review102026-06-15
0.3.56Review102026-06-12
0.3.55Review102026-06-12
0.3.54Review102026-06-12
0.3.53Review102026-06-12
0.3.52Review102026-06-12
0.3.51Review102026-06-12
0.3.50Review102026-06-12
0.3.49Review102026-06-12
0.3.48Review102026-06-11
0.3.47Review102026-06-11
0.3.46Review102026-06-11
0.3.45Review102026-06-11
0.3.44Review102026-06-11
0.3.43Review102026-06-11
0.3.42Review102026-06-11
0.3.41Review102026-06-11
0.3.40Review102026-06-10
0.3.39Review102026-06-08
0.3.38Review102026-06-03
0.3.37Review102026-06-03
0.3.35Review102026-06-03
0.3.36Review102026-06-03
0.3.33Review102026-06-03
0.3.31Review102026-06-03
0.3.32Review102026-06-03
0.3.30Review102026-06-02
0.1.0Review122026-06-01
0.3.29Review102026-06-01

Block this in CI

PkgRadar gates @lizard-build/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lizard-build/[email protected]