PkgRadar

npm · registry.npmjs.org

@ticatec/omniflow

Credential file access: matched "id_rsa"

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumCredential file accessmatched "id_rsa" · package/dist/core/ssh.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.0Review72026-05-29
0.3.16Review72026-05-28
0.3.15Review102026-05-28
0.3.12Review102026-05-28
0.3.13Review72026-05-28
0.3.10Review72026-05-27
0.3.7Review72026-05-26
0.3.8Review72026-05-26
0.3.6Review102026-05-25
0.3.5Review72026-05-25
0.3.4Review72026-05-25
0.3.3Review602026-05-24
0.2.0Low risk02026-05-24
0.3.0Review602026-05-24
0.3.1Review602026-05-24

Block this in CI

PkgRadar gates @ticatec/omniflow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ticatec/[email protected]