PkgRadar

PyPI · pypi.org

agnt

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 0.13.20

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · agnt-0.13.20/src/agnt/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · agnt-0.13.20/src/agnt/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.20High risk572026-06-16
0.13.19High risk822026-06-06
0.13.18High risk822026-06-06
0.13.17High risk822026-06-06
0.13.15High risk822026-06-04
0.13.14High risk822026-06-01
0.13.13High risk822026-06-01
0.13.12High risk822026-05-30
0.13.11High risk822026-05-30
0.13.10High risk822026-05-30

Block this in CI

PkgRadar gates agnt (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi agnt==0.13.20