PyPI · pypi.org
allotropy
Remote Payload: matched "curl "
Why PkgRadar flagged 0.1.130
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · allotropy-0.1.130/.claude/settings.local.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.136 | Low risk | 0 | 2026-06-11 |
0.1.135 | Low risk | 0 | 2026-06-10 |
0.1.134 | Low risk | 0 | 2026-06-02 |
0.1.133 | Low risk | 0 | 2026-06-02 |
0.1.132 | Low risk | 0 | 2026-06-01 |
0.1.131 | Low risk | 0 | 2026-06-01 |
0.1.130 | Review | 6 | 2026-05-27 |
0.1.129 | Review | 26 | 2026-05-26 |
Block this in CI
pkgradar gate --ecosystem pypi allotropy==0.1.130