PkgRadar

npm · registry.npmjs.org

pikiclaw

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.85

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/agent/drivers/claude.js
mediumRemote Payloadmatched "curl " · package/dist/agent/drivers/gemini.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/cli/setup-wizard.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.85Review392026-06-13
0.3.84Review392026-06-13
0.3.83Review392026-06-12
0.3.82Review392026-06-12
0.3.80Review562026-06-12
0.3.81Review562026-06-12
0.3.79Review562026-06-12
0.3.78Review562026-06-11
0.3.77Review562026-06-11
0.3.76Review562026-06-10
0.3.75Review562026-06-10
0.3.74Review392026-06-10
0.3.73Review392026-06-10
0.3.72Review392026-06-10
0.3.71Review562026-06-09
0.3.70Review562026-06-09
0.3.69Review562026-06-09
0.3.68Review562026-06-08
0.3.67Review562026-06-08
0.3.66Review392026-06-04
0.3.65Review562026-06-03
0.3.64Review562026-06-03
0.3.63Review562026-06-03
0.3.62Review562026-06-02
0.3.61Review562026-06-02
0.3.60Review562026-06-02
0.3.59Review562026-06-02
0.3.58Review562026-06-02
0.3.57Review392026-06-01
0.3.56Review612026-05-29
0.3.55Review372026-05-25
0.3.54Review542026-05-25
0.3.53Review1502026-05-24
0.3.52Review1502026-05-24
0.3.51Review1502026-05-24
0.3.50Review1502026-05-24
0.3.48Review1502026-05-24
0.3.49Review1502026-05-24

Block this in CI

PkgRadar gates pikiclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]