PkgRadar

npm · registry.npmjs.org

machinaos

Remote Payload: matched "Invoke-WebRequest"

Why PkgRadar flagged 0.0.86

SeveritySignalEvidence
mediumRemote Payloadmatched "Invoke-WebRequest" · package/.machina/workflows/AI Employee_example_workflow-1779102911870-cbc76c82.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/server/package-lock.json
mediumRemote Payloadmatched "github.com/stripe/stripe-cli/releases/download" · package/server/nodes/stripe/_install.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.90Low risk02026-06-16
0.0.8Low risk02026-06-16
0.0.7Low risk02026-06-16
0.0.9Low risk02026-06-16
0.0.89Low risk02026-06-16
0.0.88Low risk02026-06-08
0.0.86Review412026-05-27
0.0.87Review412026-05-27
0.0.84Review412026-05-27
0.0.85Review412026-05-27

Block this in CI

PkgRadar gates machinaos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]