PkgRadar

npm · registry.npmjs.org

@nano-step/ai-sandbox-wrapper

Remote Payload: matched "curl "

Why PkgRadar flagged 5.4.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/lib/install-claude.sh
mediumRemote Payloadmatched "wget " · package/lib/install-codeserver.sh
mediumRemote Payloadmatched "curl " · package/lib/install-droid.sh
mediumRemote Payloadmatched "curl " · package/lib/install-kilo.sh
mediumRemote Payloadmatched "curl " · package/lib/install-opencode.sh
mediumRemote Payloadmatched "curl " · package/lib/install-shai.sh
mediumRemote Payloadmatched "wget " · package/lib/install-vscode.sh
mediumRemote Payloadmatched "curl " · package/lib/playwright-mcp-config.sh
mediumRemote Payloadmatched "curl " · package/setup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
5.4.4Review792026-06-07
5.4.3Review792026-06-07
5.4.2Review552026-05-30
5.4.1Review552026-05-29
5.4.0Review552026-05-29
5.3.2Review792026-05-27
5.3.0Review792026-05-26
5.3.1Review792026-05-26
5.1.5Review1042026-05-25
5.1.4Review1042026-05-25
5.1.3Review1042026-05-25
5.1.2Review1042026-05-25
5.1.1Review1042026-05-25
5.1.0Review1042026-05-25
5.0.1Review1042026-05-25
5.0.0Review1042026-05-25

Block this in CI

PkgRadar gates @nano-step/ai-sandbox-wrapper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nano-step/[email protected]