npm · registry.npmjs.org
@vucinatim/agentic-devtools
Credential file access: matched ".npmrc"
Why PkgRadar flagged 0.2.4
| Severity | Signal | Evidence |
|---|---|---|
| medium | Credential file access | matched ".npmrc" · package/src/tools/npm/auth.mjs |
| medium | Credential file access | matched "NPM_TOKEN" · package/src/tools/npm/client.mjs |
| medium | Credential file access | matched ".npmrc" · package/src/tools/npm/trust-cli.mjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.2.4 | Review | 14 | 2026-05-25 |
0.2.5 | Review | 14 | 2026-05-25 |
0.2.2 | Review | 14 | 2026-05-25 |
0.2.3 | Review | 14 | 2026-05-25 |
0.1.11 | Review | 55 | 2026-05-25 |
0.1.9 | Review | 55 | 2026-05-25 |
0.1.10 | Review | 55 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm @vucinatim/[email protected]