PkgRadar

npm · registry.npmjs.org

mindforge-cc

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 11.5.1

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/bin/updater/changelog-fetcher.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/subagents/tools/subagent-catalog/config.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
11.5.1Review292026-06-11
11.5.0Review292026-06-11
11.4.0Review292026-06-05
11.3.1Review292026-06-04
11.3.0Review292026-06-04
11.2.1Review172026-05-31
11.2.0Review172026-05-31
11.0.0Review172026-05-30
10.7.0Review172026-05-30
10.0.2Review172026-05-30
10.0.3Review172026-05-30

Block this in CI

PkgRadar gates mindforge-cc (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]