PkgRadar

PyPI · pypi.org

ayase

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.1.54

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · ayase-0.1.54/src/ayase/vendor/t2v_metrics/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ayase-0.1.54/src/ayase/vendor/t2v_metrics/models/vqascore_models/tarsier/dataset/custom_data_parsers/utils.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · ayase-0.1.54/src/ayase/vendor/t2v_metrics/models/clipscore_models/umt/models/backbones/vit/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.54High risk862026-06-10
0.1.53High risk862026-05-30
0.1.52High risk862026-05-30

Block this in CI

PkgRadar gates ayase (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ayase==0.1.54