PkgRadar

npm · registry.npmjs.org

agora-agent-server-sdk

Credential file access: matched ".Azure"

Why PkgRadar flagged 1.4.1

SeveritySignalEvidence
highCredential file accessmatched ".Azure" · package/dist/cjs/agentkit/index.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/cjs/core/domain/index.js
highCredential file accessmatched ".Azure" · package/dist/cjs/index.js
highCredential file accessmatched ".Azure" · package/dist/cjs/agentkit/vendors/llm.js
highCredential file accessmatched ".AZURE" · package/dist/cjs/agentkit/vendors/stt.js
highCredential file accessmatched ".AZURE" · package/dist/cjs/agentkit/vendors/tts.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/esm/core/domain/index.mjs
highCredential file accessmatched ".AZURE" · package/dist/esm/agentkit/vendors/llm.mjs
highCredential file accessmatched ".AZURE" · package/dist/esm/agentkit/vendors/stt.mjs
highCredential file accessmatched ".AZURE" · package/dist/esm/agentkit/vendors/tts.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.1Low risk02026-06-17
2.2.0Low risk02026-06-05
2.1.1Low risk02026-06-03
2.1.0Low risk02026-06-03
1.3.2Low risk02026-05-30
1.4.0Low risk02026-05-30
2.0.0Low risk02026-05-28
2.0.1Low risk02026-05-28
1.4.1Review1502026-05-25

Block this in CI

PkgRadar gates agora-agent-server-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]