PkgRadar

npm · registry.npmjs.org

opencode-skills-collection

Remote Payload: matched "curl "

Why PkgRadar flagged 3.0.44

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bundled-skills/deploy-to-vercel/resources/deploy-codex.sh
mediumRemote Payloadmatched "curl " · package/bundled-skills/deploy-to-vercel/resources/deploy.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.44Review82026-06-13
3.0.43Review82026-06-12
3.0.42Review82026-06-10
3.0.41Review82026-06-09
3.0.40Review82026-06-08
3.0.39Review82026-06-07
3.0.38Review82026-06-06
3.0.37Review82026-06-05
3.0.36Review82026-06-04
3.0.35Review12026-06-03
3.0.34Review12026-06-02
3.0.32Review12026-06-01
3.0.33Review12026-06-01
3.0.31Review12026-05-30
3.0.30Review12026-05-29
3.0.29Review122026-05-28
3.0.28Review272026-05-27
3.0.27Review272026-05-26
3.0.26Review1482026-05-25
3.0.24Review1602026-05-24
3.0.25Review1482026-05-24

Block this in CI

PkgRadar gates opencode-skills-collection (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]