PkgRadar

npm · registry.npmjs.org

@sdsrs/sgc

Remote Payload: matched "curl "

Why PkgRadar flagged 1.9.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/src/dispatcher/agents/clarifier-discover.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.31.8Low risk02026-06-09
1.31.7Low risk02026-06-09
1.31.6Low risk02026-06-08
1.31.5Low risk02026-06-08
1.31.4Low risk02026-06-08
1.31.3Low risk02026-06-08
1.31.2Low risk02026-06-08
1.31.1Low risk02026-06-08
1.31.0Low risk02026-06-08
1.30.0Low risk02026-06-08
1.29.4Low risk02026-06-08
1.29.3Low risk02026-06-08
1.29.2Low risk02026-06-08
1.29.1Low risk02026-06-05
1.29.0Low risk02026-06-05
1.28.1Low risk02026-06-04
1.28.0Low risk02026-06-04
1.26.0Low risk02026-06-03
1.25.0Low risk02026-06-02
1.24.1Low risk02026-06-02
1.24.0Low risk02026-06-02
1.23.1Low risk02026-06-01
1.23.0Low risk02026-06-01
1.22.0Low risk02026-06-01
1.21.0Low risk02026-06-01
1.20.0Low risk02026-06-01
1.19.0Low risk02026-06-01
1.18.0Low risk02026-05-29
1.17.3Low risk02026-05-28
1.17.4Low risk02026-05-28
1.14.1Low risk02026-05-27
1.13.0Low risk02026-05-26
1.12.0Low risk02026-05-26
1.12.1Low risk02026-05-26
1.11.1Low risk02026-05-26
1.11.0Low risk02026-05-25
1.9.0Review122026-05-25
1.10.0Review122026-05-25

Block this in CI

PkgRadar gates @sdsrs/sgc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @sdsrs/[email protected]