PkgRadar

npm · registry.npmjs.org

repo-harness

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 0.4.3

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/assets/templates/helpers/check-agent-tooling.sh
mediumRemote Payloadmatched "curl " · package/assets/templates/helpers/check-context-files.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.3Review292026-06-12
0.4.2Review292026-06-12
0.4.1Review292026-06-12
0.4.0Review202026-06-12
0.3.0Review292026-06-10
0.2.4Review202026-06-07
0.2.3Review292026-06-05
0.2.2Review202026-06-04
0.2.1Review292026-06-01
0.2.0Review292026-06-01
0.1.5Review292026-05-31
0.1.4Review292026-05-31
0.1.3Review292026-05-31
0.1.2Review292026-05-30
0.1.1Review292026-05-28
0.1.0Review292026-05-28

Block this in CI

PkgRadar gates repo-harness (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]