PkgRadar

npm · registry.npmjs.org

freddie

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.0.121

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/plugins/skills_hub/handler.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/cli/skills_hub.js
mediumRemote Dependency Specdependencies.@anentrypoint/libsql-plugkit-client="github:AnEntrypoint/libsql-plugkit-client" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.121Review562026-05-26
0.0.120Review562026-05-26
0.0.118Review562026-05-25
0.0.117Review562026-05-25
0.0.116Review1362026-05-24
0.0.114Review1362026-05-24
0.0.115Review1362026-05-24

Block this in CI

PkgRadar gates freddie (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]