PkgRadar

npm · registry.npmjs.org

100xprism

Remote Payload, Suspicious Publish Context

Why PkgRadar flagged 2.3.3

SeveritySignalEvidence
mediumRemote Payloadpackage/adapters/claude-code.sh
mediumSuspicious Publish Context

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.3Review222026-06-21
2.3.4Review222026-06-21
2.3.2Review222026-06-21
2.3.1Review122026-06-21

Block this in CI

PkgRadar gates 100xprism (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]