PkgRadar

npm · registry.npmjs.org

create-spec-kit

Credential File Packaged: package/scaffold/.github/skills/claudeskill-loki-mode/.env

Why PkgRadar flagged 1.1.0

SeveritySignalEvidence
highCredential File Packagedpackage/scaffold/.github/skills/claudeskill-loki-mode/.env · package/scaffold/.github/skills/claudeskill-loki-mode/.env
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/scaffold/.github/skills/claudeskill-loki-mode/blog/js/main.js
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/app-runner.sh
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/notify.sh
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/sandbox.sh
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/serve.sh
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/telemetry.sh
mediumRemote Payloadmatched "curl " · package/scaffold/.github/skills/claudeskill-loki-mode/autonomy/voice.sh
mediumSuspicious Publish Context{"package_age_days":0,"publisher":"alive_phoenix","burst_same_day":1,"burst_week":1,"lure":null,"version_anomaly":false,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0High risk1222026-06-15
1.0.0High risk1222026-06-15

Block this in CI

PkgRadar gates create-spec-kit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]