PkgRadar

PyPI · pypi.org

agenticx

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.4.2

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · agenticx-0.4.2/agenticx/cli/agent_tools.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · agenticx-0.4.2/agenticx/longrun/studio_routes.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · agenticx-0.4.2/agenticx/studio/voice_endpoints.py
mediumCredential file accessmatched "aws_access_key" · agenticx-0.4.2/agenticx/integrations/mem0/embeddings/aws_bedrock.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · agenticx-0.4.2/agenticx/integrations/mem0/embeddings/vertexai.py
mediumCredential file accessmatched "aws_access_key" · agenticx-0.4.2/agenticx/integrations/mem0/llms/aws_bedrock.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.2High risk1102026-06-06
0.4.1High risk1052026-05-30

Block this in CI

PkgRadar gates agenticx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi agenticx==0.4.2