PkgRadar

npm · registry.npmjs.org

@vicoa/cli

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 1.5.8-win32-x64

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/bin/_internal/integrations/github/claude-code-action/src/mcp/github-file-ops-server.ts
highCredential file accessmatched "AWS_ACCESS_KEY" · package/bin/_internal/integrations/github/claude-code-action/base-action/src/run-vicoa.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.8-win32-x64Review212026-06-13
1.5.8Low risk02026-06-13
1.5.7-win32-x64Review212026-06-08
1.5.7Low risk02026-06-08
1.5.6-win32-x64Review212026-06-06
1.5.6Low risk02026-06-06
1.5.5-intel-test.0Low risk02026-06-04
1.5.5-win32-x64Review212026-06-04
1.5.5Low risk02026-06-04
1.5.4-win32-x64Review122026-06-03
1.5.4Low risk02026-06-03
1.5.3-win32-x64Review122026-05-30
1.5.3Low risk02026-05-30
1.5.2-win32-x64Review332026-05-28
1.5.2Low risk02026-05-28

Block this in CI

PkgRadar gates @vicoa/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vicoa/[email protected]