PkgRadar

npm · registry.npmjs.org

copilot-deck

Known Indicator Filename: package/dist/lib/bundle.js

Why PkgRadar flagged 0.1.5

SeveritySignalEvidence
highKnown Indicator Filenamepackage/dist/lib/bundle.js · package/dist/lib/bundle.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist-bundle/web/assets/chunk-727SXJPM-Dgiqi2fO.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist-bundle/web/assets/flowDiagram-I6XJVG4X-CbMNHcpV.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.5Review742026-05-25
0.1.4Review752026-05-24
0.1.0Review752026-05-24
0.1.1Review752026-05-24

Block this in CI

PkgRadar gates copilot-deck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]