npm · registry.npmjs.org
@mseep/delimit-cli
New Account With Lifecycle Hook, Remote Payload, Credential file access +1 more
Why PkgRadar flagged 4.13.1
| Severity | Signal | Evidence |
|---|---|---|
| high | New Account With Lifecycle Hook | package.json |
| medium | Remote Payload | package/bin/delimit-setup.js |
| medium | Credential file access | package/gateway/ai/server.py |
| medium | Credential file access | package/gateway/ai/backends/tools_infra.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.13.1 | High risk | 57 | 2026-06-22 |
Related campaigns
- Publisher burst: skydeckai — 20 releases, max score 85
Block this in CI
pkgradar gate --ecosystem npm @mseep/[email protected]