PyPI · pypi.org
auto-coder
Py Import Time Subprocess: subprocess call — process spawning.
Why PkgRadar flagged 3.0.56
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Import Time Subprocess | subprocess call — process spawning. · auto_coder-3.0.56/src/autocoder/common/__init__.py |
| medium | Py Import Time Subprocess | subprocess call — process spawning. · auto_coder-3.0.56/src/autocoder/utils/__init__.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · auto_coder-3.0.56/src/autocoder/utils/_markitdown.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.0.56 | High risk | 40 | 2026-06-04 |
Block this in CI
pkgradar gate --ecosystem pypi auto-coder==3.0.56