PkgRadar

npm · registry.npmjs.org

@skyramp/mcp

Remote Payload: matched "curl "

Why PkgRadar flagged 0.2.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/node_modules/playwright/node_modules/playwright-core/bin/reinstall_chrome_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/node_modules/playwright/node_modules/playwright-core/bin/reinstall_chrome_stable_mac.sh
mediumRemote Payloadmatched "curl " · package/node_modules/playwright/node_modules/playwright-core/bin/reinstall_msedge_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/node_modules/playwright/node_modules/playwright-core/bin/reinstall_msedge_dev_mac.sh
mediumRemote Payloadmatched "curl " · package/node_modules/playwright/node_modules/playwright-core/bin/reinstall_msedge_stable_mac.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.5Review352026-06-11
0.2.5-rc.3Review352026-06-11
0.2.5-rc.2Review352026-06-11
0.2.5-rc.1Review352026-06-10
0.2.4Review352026-06-09
0.2.3Review352026-06-09
0.2.2Review352026-06-08
0.2.150-rc.sutReview352026-06-05
0.2.1Review352026-06-04
0.2.0Review352026-06-03
0.2.1-rc.1Review352026-06-03
0.2.0-rc.3Review512026-05-28
0.2.0-rc.1Review512026-05-27
0.2.0-rc.2Review512026-05-27

Block this in CI

PkgRadar gates @skyramp/mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @skyramp/[email protected]