PkgRadar

npm · registry.npmjs.org

openspec-playwright

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.26

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/commands/audit.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.43Low risk02026-06-12
0.3.42Low risk02026-06-12
0.3.41Low risk02026-06-12
0.3.40Low risk02026-06-11
0.3.39Low risk02026-06-11
0.3.38Low risk02026-06-11
0.3.37Low risk02026-06-11
0.3.36Low risk02026-06-11
0.3.35Low risk02026-06-10
0.3.34Low risk02026-06-09
0.3.33Low risk02026-06-09
0.3.32Low risk02026-06-05
0.3.31Low risk02026-06-04
0.3.30Low risk02026-06-03
0.3.29Low risk02026-06-03
0.3.27Low risk02026-06-03
0.3.26Review122026-06-02
0.3.25Review122026-06-02

Block this in CI

PkgRadar gates openspec-playwright (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]