PkgRadar

npm · registry.npmjs.org

@orchid-ai/orchid-mcp

Ci Workflow Secret Harvesting: workflow references CI/cloud credential harvesting surfaces

Why PkgRadar flagged 1.2.4

SeveritySignalEvidence
highCi Workflow Secret Harvestingworkflow references CI/cloud credential harvesting surfaces · package/.github/workflows/orchid-mcp-release.yml
mediumRemote Payloadmatched "curl " · package/.github/workflows/orchid-mcp-release.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.4Review182026-05-27
0.1.0-devLow risk02026-05-27

Block this in CI

PkgRadar gates @orchid-ai/orchid-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @orchid-ai/[email protected]