PkgRadar

PyPI · pypi.org

agentic-ci

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.3.3

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · agentic_ci-0.3.3/src/agentic_ci/backends/podman.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `uv_build` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "curl " · agentic_ci-0.3.3/src/agentic_ci/jira/acli.py
mediumCredential file accessmatched ".config/gcloud" · agentic_ci-0.3.3/src/agentic_ci/backends/podman.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · agentic_ci-0.3.3/src/agentic_ci/harness.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.3High risk822026-06-17
0.3.2High risk822026-06-16
0.3.1High risk822026-06-16
0.3.0High risk822026-06-12
0.2.25High risk822026-06-11
0.2.24High risk822026-06-11
0.2.23High risk822026-06-09
0.2.22High risk822026-06-09
0.2.21High risk822026-06-09
0.2.20High risk822026-06-08
0.2.19High risk822026-06-05
0.2.18High risk822026-06-04
0.2.17High risk822026-06-04
0.2.16High risk822026-06-03
0.2.15High risk822026-06-03
0.2.14High risk822026-06-02
0.2.13High risk822026-05-30
0.2.12High risk822026-05-30
0.2.11High risk822026-05-30
0.2.10High risk822026-05-30

Block this in CI

PkgRadar gates agentic-ci (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi agentic-ci==0.3.3