PkgRadar

PyPI · pypi.org

automated-sing-box-generator

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.18

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · automated_sing_box_generator-0.3.18/src/automated_sing_box_generator/installer.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.18Review122026-06-11
0.3.17Review122026-06-06
0.3.16Review122026-06-01
0.3.15Review122026-06-01
0.3.14Review122026-06-01
0.3.13Review122026-06-01
0.3.12Review122026-05-31
0.3.11Review122026-05-30
0.3.9Review122026-05-30
0.3.8Review122026-05-30
0.3.7Review122026-05-30
0.3.6Review122026-05-30

Block this in CI

PkgRadar gates automated-sing-box-generator (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi automated-sing-box-generator==0.3.18