PkgRadar

npm · registry.npmjs.org

@optima-chat/dev-skills

Credential file access: matched ".ssh/"

Why PkgRadar flagged 0.7.41

SeveritySignalEvidence
highCredential file accessmatched ".ssh/" · package/bin/helpers/db-utils.ts
mediumRemote Payloadmatched "curl " · package/bin/helpers/billing-http.ts
mediumRemote Payloadmatched "curl " · package/bin/helpers/db-utils.ts
mediumRemote Payloadmatched "curl " · package/bin/helpers/infisical-secrets.ts
mediumRemote Payloadmatched "curl " · package/bin/helpers/show-env.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.41High risk612026-06-12
0.7.40High risk612026-06-12
0.7.37High risk732026-06-10
0.7.38High risk632026-06-10
0.7.36High risk732026-06-10
0.7.33High risk632026-06-10
0.7.35High risk732026-06-10

Related campaigns

Block this in CI

PkgRadar gates @optima-chat/dev-skills (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @optima-chat/[email protected]