npm · registry.npmjs.org
stop-wasting-tokens
Remote Payload: matched "curl "
Why PkgRadar flagged 3.0.0-alpha.90
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · package/scripts/bash-guard.sh |
| medium | Remote Payload | matched "curl " · package/scripts/swt-statusline.sh |
| medium | Remote Payload | matched "curl " · package/scripts/test-audit-upstream-prompts.sh |
| medium | Large Javascript Payload | 15411752 bytes · package/dist/cli.mjs |
| medium | Large Javascript Payload | 23483832 bytes · package/dist/dashboard-server.mjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.0.0-alpha.90 | Review | 18 | 2026-05-25 |
3.0.0-alpha.88 | Review | 18 | 2026-05-25 |
3.0.0-alpha.89 | Review | 18 | 2026-05-25 |
3.0.0-alpha.86 | Review | 18 | 2026-05-25 |
3.0.0-alpha.87 | Review | 18 | 2026-05-25 |
3.0.0-alpha.84 | Review | 18 | 2026-05-25 |
3.0.0-alpha.83 | Review | 18 | 2026-05-25 |
3.0.0-alpha.82 | Review | 100 | 2026-05-25 |
3.0.0-alpha.71 | Review | 100 | 2026-05-24 |
3.0.0-alpha.70 | Review | 100 | 2026-05-24 |
3.0.0-alpha.67 | Review | 100 | 2026-05-24 |
3.0.0-alpha.69 | Review | 100 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]