PkgRadar

PyPI · pypi.org

aegis-ai

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.7.4

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · aegis_ai-0.7.4/src/aegis_ai/toolsets/tools/kernel_cves/__init__.py
mediumRemote Payloadmatched "curl " · aegis_ai-0.7.4/evals/features/cve/generate_kernel_eval_csv.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.4Review382026-06-05
0.7.3Review382026-06-05

Block this in CI

PkgRadar gates aegis-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aegis-ai==0.7.4