PkgRadar

PyPI · pypi.org

aimu

Py Runtime Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.4.0

SeveritySignalEvidence
mediumPy Runtime Subprocesssubprocess call — process spawning. · aimu-0.4.0/aimu/skills/mcp.py
mediumPy Runtime Eval ExecPython eval()/exec() called on a string. · aimu-0.4.0/aimu/tools/builtin.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.1Low risk02026-06-17
0.9.0Low risk02026-06-17
0.7.0Low risk02026-06-08
0.6.0Low risk02026-06-04
0.5.1Low risk02026-06-01
0.5.0Low risk02026-06-01
0.4.0Review282026-05-26

Block this in CI

PkgRadar gates aimu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aimu==0.4.0