PkgRadar

PyPI · pypi.org

ai-parrot-tools

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.1.67

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ai_parrot_tools-0.1.67/src/parrot_tools/sandboxtool.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.67High risk552026-06-13
0.1.66High risk552026-06-11
0.1.65High risk552026-06-11
0.1.64High risk552026-06-10
0.1.63High risk552026-06-10
0.1.62High risk552026-06-10
0.1.61High risk552026-06-08
0.1.60High risk552026-06-06
0.1.59High risk552026-06-03
0.1.58High risk552026-06-03
0.1.57High risk552026-06-02
0.1.56High risk552026-05-30
0.1.54High risk552026-05-30
0.1.53High risk552026-05-30

Block this in CI

PkgRadar gates ai-parrot-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ai-parrot-tools==0.1.67