npm · registry.npmjs.org
@vicoa/cli
Credential file access: matched "GITHUB_TOKEN"
Why PkgRadar flagged 1.5.8-win32-x64
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched "GITHUB_TOKEN" · package/bin/_internal/integrations/github/claude-code-action/src/mcp/github-file-ops-server.ts |
| high | Credential file access | matched "AWS_ACCESS_KEY" · package/bin/_internal/integrations/github/claude-code-action/base-action/src/run-vicoa.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.5.8-win32-x64 | Review | 21 | 2026-06-13 |
1.5.8 | Low risk | 0 | 2026-06-13 |
1.5.7-win32-x64 | Review | 21 | 2026-06-08 |
1.5.7 | Low risk | 0 | 2026-06-08 |
1.5.6-win32-x64 | Review | 21 | 2026-06-06 |
1.5.6 | Low risk | 0 | 2026-06-06 |
1.5.5-intel-test.0 | Low risk | 0 | 2026-06-04 |
1.5.5-win32-x64 | Review | 21 | 2026-06-04 |
1.5.5 | Low risk | 0 | 2026-06-04 |
1.5.4-win32-x64 | Review | 12 | 2026-06-03 |
1.5.4 | Low risk | 0 | 2026-06-03 |
1.5.3-win32-x64 | Review | 12 | 2026-05-30 |
1.5.3 | Low risk | 0 | 2026-05-30 |
1.5.2-win32-x64 | Review | 33 | 2026-05-28 |
1.5.2 | Low risk | 0 | 2026-05-28 |
Block this in CI
pkgradar gate --ecosystem npm @vicoa/[email protected]