PkgRadar

npm · registry.npmjs.org

@mseep/claude-code-source

Js Hidden Powershell, Remote Payload, Credential file access

Why PkgRadar flagged 2.1.152

SeveritySignalEvidence
highJs Hidden Powershellpackage/src/tools/PowerShellTool/pathValidation.ts
highJs Hidden Powershellpackage/src/utils/permissions/permissions.ts
highJs Hidden Powershellpackage/src/utils/permissions/yoloClassifier.ts
mediumRemote Payloadpackage/start-ollama.sh
mediumRemote Payloadpackage/src/utils/plugins/installCounts.ts
mediumRemote Payloadpackage/src/utils/releaseNotes.ts

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.152Review992026-06-22

Block this in CI

PkgRadar gates @mseep/claude-code-source (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @mseep/[email protected]