PkgRadar

PyPI · pypi.org

agent-security-harness

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 4.5.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · agent_security_harness-4.5.0/protocol_tests/capability_profile_harness.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · agent_security_harness-4.5.0/protocol_tests/mcp_supplychain.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · agent_security_harness-4.5.0/protocol_tests/watermark_harness.py
mediumRemote Payloadmatched "curl " · agent_security_harness-4.5.0/protocol_tests/cloud_agent_harness.py
mediumRemote Payloadmatched "curl " · agent_security_harness-4.5.0/protocol_tests/crewai_cve_harness.py
mediumRemote Payloadmatched "curl " · agent_security_harness-4.5.0/protocol_tests/extended_enterprise_adapters.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.5.0High risk1612026-06-09

Block this in CI

PkgRadar gates agent-security-harness (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi agent-security-harness==4.5.0