PkgRadar

npm · registry.npmjs.org

@pencil-agent/nano-pencil

Remote Payload: matched "curl "

Why PkgRadar flagged 2.0.3

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/extensions/builtin/browser/src/browser_harness/admin.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.3Review182026-06-13
2.0.2Review182026-06-13
2.0.1Review182026-06-12
2.0.0Review182026-06-12
2.0.0-beta.10Review182026-06-12
2.0.0-beta.9Review182026-06-12
2.0.0-beta.8Review272026-06-11
1.11.40Review762026-06-11
2.0.0-beta.7Review272026-06-11
1.11.39Review762026-06-11
2.0.0-beta.3Review272026-06-11
1.11.38Review762026-06-11
2.0.0-beta.4Review272026-06-05
2.0.0-beta.6Review272026-06-05
2.0.0-beta.1Review222026-06-05
2.0.0-beta.0Review222026-06-05
1.14.6Review322026-05-28
1.14.5Review322026-05-28
1.14.4Review422026-05-27
1.14.3Review422026-05-27
1.14.1Review472026-05-26
1.14.2Review422026-05-26

Block this in CI

PkgRadar gates @pencil-agent/nano-pencil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pencil-agent/[email protected]