PkgRadar

npm · registry.npmjs.org

@lumenflow/control-plane-sdk

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 5.10.8

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/agent-host-registry.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.10.8High risk402026-06-01
5.8.15High risk402026-06-01

Block this in CI

PkgRadar gates @lumenflow/control-plane-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lumenflow/[email protected]