PkgRadar

npm · registry.npmjs.org

@tbosancheros39/opencode-outpost

Remote Payload: matched "curl "

Why PkgRadar flagged 0.16.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/cli/doctor.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.16.2Review122026-06-06
0.15.1Review122026-06-06
0.16.1Review122026-06-06

Block this in CI

PkgRadar gates @tbosancheros39/opencode-outpost (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tbosancheros39/[email protected]