PkgRadar

npm · registry.npmjs.org

egregore-init

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.19

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/dashboard-data.sh
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/graph-batch.sh
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/graph.sh
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/lib/identity.sh
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/notify.sh
mediumRemote Payloadmatched "curl " · package/runtime/codex/bin/telemetry.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.19Review352026-06-16
0.10.18Review352026-06-16
0.10.17Low risk02026-06-15
0.10.16Low risk02026-06-11
0.10.15Low risk02026-06-11
0.10.14Low risk02026-06-11
0.10.13Low risk02026-06-10
0.10.12Low risk02026-06-09
0.10.11Low risk02026-06-09
0.10.10Low risk02026-06-09
0.10.9Low risk02026-06-09
0.10.8Low risk02026-05-30
0.10.7Review152026-05-29
0.10.5Review152026-05-28
0.10.4Review152026-05-28
0.10.3Review152026-05-28
0.10.2Review152026-05-28
0.10.1Review152026-05-28

Block this in CI

PkgRadar gates egregore-init (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]