PkgRadar

npm · registry.npmjs.org

thegitbot

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 1.2.74-beta.10

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/setup/lib/prerequisites.mjs
highCredential file accessmatched "GITHUB_TOKEN" · package/templates/.github/workflows/run-job.yml
mediumRemote Payloadmatched "curl " · package/lib/cluster/components/cluster-page.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/templates/skills/brave-search/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/templates/skills/browser-tools/package-lock.json
mediumRemote Payloadmatched "curl " · package/templates/skills/google-docs/create.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/google-drive/delete.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/google-drive/download.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/kie-ai/generate-image.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/kie-ai/generate-video.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/google-drive/list.sh
mediumRemote Payloadmatched "curl " · package/templates/skills/google-drive/upload.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.74-beta.10Review1002026-05-24

Block this in CI

PkgRadar gates thegitbot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]