PkgRadar

npm · registry.npmjs.org

vibecarbon

Remote Payload: matched "curl "

Why PkgRadar flagged 0.5.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/carbon/cloud-init/k3s/master-init.sh
mediumRemote Payloadmatched "curl " · package/carbon/cloud-init/k3s/supabase-init.sh
mediumRemote Payloadmatched "curl " · package/carbon/k8s/test-local.sh
mediumRemote Payloadmatched "curl " · package/carbon/cloud-init/k3s/worker-init.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.1Review622026-06-03
0.5.0Review622026-06-02
0.4.0Review502026-05-31
0.2.0Review502026-05-30
0.1.6Review662026-05-30
0.1.7Review462026-05-30
0.3.1Review502026-05-29
0.3.0Review502026-05-29
0.2.1Review1422026-05-28

Block this in CI

PkgRadar gates vibecarbon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]