PkgRadar

npm · registry.npmjs.org

@research-copilot/plugin

Remote Payload: matched "curl "

Why PkgRadar flagged 1.1.18

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/skills/llm-wiki/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.18Review122026-06-16
1.1.16Low risk02026-06-16
1.1.17Low risk02026-06-16
1.1.15Low risk02026-06-16

Block this in CI

PkgRadar gates @research-copilot/plugin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @research-copilot/[email protected]