PkgRadar

npm · registry.npmjs.org

ummaya

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/src/ummaya/safety/_patterns.py
highCredential file accessmatched ".npmrc" · package/tui/src/utils/autoUpdater.ts
highCredential file accessmatched ".aws" · package/tui/src/utils/aws.ts
highCredential file accessmatched "KUBECONFIG" · package/tui/src/tools/BashTool/bashPermissions.ts
highCredential file accessmatched ".ssh" · package/tui/src/tools/BashTool/bashSecurity.ts
highCredential file accessmatched ".azure" · package/src/ummaya/llm/_cc_reference/client.ts
highCredential file accessmatched ".ssh" · package/tui/src/utils/permissions/dangerousPatterns.ts
highCredential file accessmatched ".AWS" · package/tui/src/utils/env.ts
highCredential file accessmatched ".AWS" · package/tui/src/utils/envUtils.ts
highCredential file accessmatched ".azure" · package/tui/src/utils/plugins/fetchTelemetry.ts
highCredential file accessmatched ".ssh" · package/tui/src/utils/permissions/filesystem.ts
highCredential file accessmatched ".ssh" · package/tui/src/utils/fsOperations.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.4Review292026-05-31
0.2.3Review532026-05-25
0.2.2Review532026-05-25
0.2.1Review2302026-05-24
0.2.0Review2302026-05-24
0.0.0-namecheckLow risk02026-05-24
0.1.0High risk2302026-05-24
0.1.2Review2302026-05-24
0.1.3Review2302026-05-24
0.1.5Review2302026-05-24
0.1.6High risk2302026-05-24
0.1.7Review2302026-05-24
0.1.8Review2302026-05-24
0.1.11Review2302026-05-24
0.1.12Review2302026-05-24
0.1.14Review2302026-05-24
0.1.15Review2302026-05-24
0.1.17Review2302026-05-24
0.1.18Review2302026-05-24

Related campaigns

Block this in CI

PkgRadar gates ummaya (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]