PkgRadar

npm · registry.npmjs.org

@yan162/changewayguard

Credential file access: matched ".ssh/"

Why PkgRadar flagged 6.8.27

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · package/dist/agent/openclaw-hybrid-audit-changeway.js

Scanned versions

VersionVerdictScoreScanned (UTC)
6.8.27Review102026-06-09
6.8.25Review102026-06-09
6.8.26Review102026-06-09

Block this in CI

PkgRadar gates @yan162/changewayguard (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @yan162/[email protected]