PkgRadar

npm · registry.npmjs.org

agentvibes

Remote Payload: matched "Invoke-WebRequest"

Why PkgRadar flagged 5.10.1

SeveritySignalEvidence
mediumRemote Payloadmatched "Invoke-WebRequest" · package/src/console/tabs/voices-tab.js
mediumRemote Payloadmatched "github.com/rhasspy/piper/releases/download" · package/.claude/hooks/piper-installer.sh
mediumRemote Payloadmatched "curl " · package/.claude/hooks/termux-installer.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
5.10.1High risk422026-06-10
5.9.0High risk422026-06-10

Block this in CI

PkgRadar gates agentvibes (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]