PkgRadar

npm · registry.npmjs.org

@songsid/agend

Remote Payload: matched "curl "

Why PkgRadar flagged 0.0.24-beta.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/cli.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/quickstart.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/setup-wizard.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/topic-commands.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.24-beta.5Review442026-06-13
0.0.24-beta.4Review442026-06-13
0.0.24-beta.3Review442026-06-13
0.0.24-beta.2Review442026-06-13
0.0.24-beta.1Review442026-06-13
0.0.23Review442026-06-12
0.0.22-beta.7Review632026-06-12
0.0.22-beta.6Review632026-06-12
0.0.22-beta.5Review442026-06-12
0.0.22-beta.4Review442026-06-12
0.0.22-beta.3Review442026-06-12
0.0.22-beta.2Review442026-06-12
0.0.22Review442026-06-12
0.0.22-beta.1Review442026-06-12
0.0.21Review442026-06-12
0.0.21-beta.1Review442026-06-12
0.0.20Review442026-06-12
0.0.20-beta.2Review442026-06-12
0.0.20-beta.1Review442026-06-12
0.0.19Review442026-06-11
0.0.18Review632026-06-11
0.0.18-beta.1Review442026-06-11
0.0.17Review442026-06-11
0.0.17-beta.8Review632026-06-10
0.0.17-beta.7Review632026-06-10
0.0.17-beta.6Review632026-06-10
0.0.17-beta.5Review632026-06-10
0.0.17-beta.4Review442026-06-10
0.0.17-beta.3Review632026-06-09
0.0.17-beta.2Review442026-06-09
0.0.17-beta.1Review442026-06-08
0.0.16-beta.6Review632026-06-03
0.0.16Review442026-06-03
0.0.16-beta.4Review442026-06-03
0.0.16-beta.5Review442026-06-03
0.0.16-beta.1Review632026-06-03
0.0.15Review632026-06-02
0.0.13Review632026-06-02
0.0.14Review632026-06-02
0.0.11Review632026-06-01
0.0.9Review632026-05-29
0.0.10Review442026-05-29
0.0.8Review362026-05-25
0.0.6Review362026-05-25
0.0.7Review362026-05-25

Block this in CI

PkgRadar gates @songsid/agend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @songsid/[email protected]