PkgRadar

npm · registry.npmjs.org

pi-agent-flow

Remote Payload: matched "curl\n "

Why PkgRadar flagged 2.2.13

SeveritySignalEvidence
mediumRemote Payloadmatched "curl\n " · package/dist/tools/web-ops.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.6Low risk02026-06-12
2.3.5Low risk02026-06-03
2.3.4Low risk02026-06-03
2.3.2Low risk02026-06-03
2.3.3Low risk02026-06-03
2.3.1Low risk02026-06-02
2.3.0Low risk02026-06-02
2.2.33Low risk02026-06-01
2.2.32Low risk02026-06-01
2.2.31Low risk02026-06-01
2.2.30Low risk02026-05-31
2.2.29Low risk02026-05-31
2.2.28Low risk02026-05-31
2.2.27Low risk02026-05-30
2.2.26Low risk02026-05-29
2.2.24Low risk02026-05-28
2.2.23Low risk02026-05-28
2.2.21Low risk02026-05-28
2.2.22Low risk02026-05-28
2.2.20Low risk02026-05-27
2.2.18Low risk02026-05-27
2.2.19Low risk02026-05-27
2.2.16Low risk02026-05-27
2.2.17Low risk02026-05-27
2.2.14Low risk02026-05-26
2.2.13Review122026-05-24
2.2.12Review122026-05-24
2.2.11Review122026-05-24
2.2.10Review122026-05-24
2.2.9Review122026-05-24
2.2.8Review122026-05-24
2.2.6Review122026-05-24

Block this in CI

PkgRadar gates pi-agent-flow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]