PkgRadar

PyPI · pypi.org

aimux

Credential file access: matched ".ssh/"

Why PkgRadar flagged 0.1.2

SeveritySignalEvidence
mediumCredential file accessmatched ".ssh/" · aimux-0.1.2/1a6aa920/src/aimux/cli.py
mediumCredential file accessmatched ".ssh/" · aimux-0.1.2/283a4107/src/aimux/cli.py
mediumCredential file accessmatched ".ssh/" · aimux-0.1.2/2fdacb03/src/aimux/cli.py
mediumCredential file accessmatched ".ssh/" · aimux-0.1.2/9cb32feb/src/aimux/cli.py
mediumCredential file accessmatched ".ssh/" · aimux-0.1.2/src/aimux/cli.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.2Review502026-06-01
0.1.1Review102026-05-30

Block this in CI

PkgRadar gates aimux (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aimux==0.1.2