PkgRadar

PyPI · pypi.org

aicage

Remote Payload: matched "curl "

Why PkgRadar flagged 1.2.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/agy/install.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/agy/version.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/claude/install.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/crush/install.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/droid/install.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/droid/version.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/goose/install.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/goose/version.sh
mediumRemote Payloadmatched "curl " · aicage-1.2.5/config/agent-build/agents/opencode/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.5High risk502026-06-05

Block this in CI

PkgRadar gates aicage (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aicage==1.2.5
aicage — PyPI security scan | PkgRadar