PkgRadar

PyPI · pypi.org

aipass

Py Import Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Why PkgRadar flagged 2.5.3

SeveritySignalEvidence
highPy Import Time Os SystemDirect shell invocation via os.system / os.popen / os.exec*. · aipass-2.5.3/src/aipass/aipass/apps/handlers/handoff_platform/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · aipass-2.5.3/src/aipass/aipass/apps/handlers/handoff_platform/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · aipass-2.5.3/src/aipass/aipass/apps/handlers/ping_sweep/__init__.py
mediumRemote Payloadmatched "curl " · aipass-2.5.3/setup.sh
mediumRemote Payloadmatched "curl " · aipass-2.5.3/src/aipass/aipass/apps/modules/init_flow.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.3High risk1242026-06-11
2.5.2High risk1122026-06-08
2.5.1High risk1122026-06-08
2.5.0High risk1122026-05-30
2.4.0High risk1122026-05-30

Block this in CI

PkgRadar gates aipass (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aipass==2.5.3