PkgRadar

npm · registry.npmjs.org

@optima-chat/optima-agent

Remote Payload: matched "curl "

Why PkgRadar flagged 0.11.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/bin/serve.js
mediumRemote Payloadmatched "curl " · package/dist/src/system-prompt.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.16.1Low risk02026-06-08
0.16.0Low risk02026-06-07
0.15.8Low risk02026-06-05
0.15.7Low risk02026-06-02
0.15.6Low risk02026-06-02
0.15.5Low risk02026-06-02
0.15.4Low risk02026-06-01
0.15.3Low risk02026-06-01
0.15.2Low risk02026-06-01
0.15.1Low risk02026-05-31
0.15.0Low risk02026-05-31
0.14.1Low risk02026-05-26
0.14.2Low risk02026-05-26
0.13.1Low risk02026-05-26
0.13.0Low risk02026-05-26
0.13.0-next.0Low risk02026-05-25
0.12.1Low risk02026-05-25
0.11.5Review242026-05-24
0.12.0Review242026-05-24

Block this in CI

PkgRadar gates @optima-chat/optima-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @optima-chat/[email protected]