PkgRadar

npm · registry.npmjs.org

@testdriverai/mcp

Remote Payload: matched "Invoke-WebRequest"

Why PkgRadar flagged 7.9.104-test

SeveritySignalEvidence
mediumRemote Payloadmatched "Invoke-WebRequest" · package/setup/aws/spawn-runner.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
7.9.104-testReview172026-06-12
7.9.103-canaryReview172026-06-12
7.9.103-testReview172026-06-12
7.9.102-testReview172026-06-12
7.9.101-testReview172026-06-12
7.9.100-canaryReview112026-06-10
7.9.3Review52026-06-10
7.9.100-testReview172026-06-10
7.9.99-testReview112026-06-08
7.9.99-canaryReview172026-06-08
7.9.98-canaryReview112026-05-30
7.9.98-testReview112026-05-30
7.9.97-testReview182026-05-28
7.9.97-canaryReview182026-05-28
7.9.96-canaryReview422026-05-28
7.9.95-testReview422026-05-28
7.9.96-testReview422026-05-28

Block this in CI

PkgRadar gates @testdriverai/mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @testdriverai/[email protected]