PkgRadar

npm · registry.npmjs.org

@ouro.bot/cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.1.0-alpha.668

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/heart/daemon/skill-management-installer.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0-alpha.668Review32026-06-12
0.1.0-alpha.667Review32026-06-12
0.1.0-alpha.666Review32026-06-12
0.1.0-alpha.665Review32026-06-10
0.1.0-alpha.663Review32026-06-10
0.1.0-alpha.664Review32026-06-10
0.1.0-alpha.662Review32026-06-10
0.1.0-alpha.661Review32026-06-09
0.1.0-alpha.660Review32026-06-09
0.1.0-alpha.659Review32026-06-09
0.1.0-alpha.658Review32026-06-09
0.1.0-alpha.636Review202026-05-27
0.1.0-alpha.657Review202026-05-27
0.1.0-alpha.654Review202026-05-26
0.1.0-alpha.655Review202026-05-26
0.1.0-alpha.653Review432026-05-25
0.1.0-alpha.652Review912026-05-25
0.1.0-alpha.651Review1312026-05-25
0.1.0-alpha.650Review1312026-05-25
0.1.0-alpha.649Review1312026-05-25
0.1.0-alpha.648Review1342026-05-25
0.1.0-alpha.647Review1342026-05-25
0.1.0-alpha.646Review1482026-05-25
0.1.0-alpha.645Review1482026-05-25
0.1.0-alpha.644Review1482026-05-25
0.1.0-alpha.643Review1482026-05-24
0.1.0-alpha.642Review1482026-05-24
0.1.0-alpha.641Review1482026-05-24
0.1.0-alpha.640Review1482026-05-24
0.1.0-alpha.639Review1482026-05-24
0.1.0-alpha.638Review1482026-05-24
0.1.0-alpha.637Review1482026-05-24
0.1.0-alpha.612Review1482026-05-24

Block this in CI

PkgRadar gates @ouro.bot/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ouro.bot/[email protected]