PyPI · pypi.org
behemot-framework
Webhook Exfil Endpoint: matched "api.telegram.org/bot"
Why PkgRadar flagged 0.5.5
| Severity | Signal | Evidence |
|---|---|---|
| high | Webhook Exfil Endpoint | matched "api.telegram.org/bot" · behemot_framework-0.5.5/behemot_framework/startup.py |
| high | Webhook Exfil Endpoint | matched "api.telegram.org/bot" · behemot_framework-0.5.5/behemot_framework/startup_backup.py |
| medium | Credential file access | matched "aws_access_key" · behemot_framework-0.5.5/behemot_framework/rag/document_loader.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · behemot_framework-0.5.5/behemot_framework/startup.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · behemot_framework-0.5.5/behemot_framework/startup_backup.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.5.5 | High risk | 85 | 2026-06-06 |
0.5.4 | High risk | 85 | 2026-06-06 |
0.5.3 | High risk | 85 | 2026-06-06 |
Block this in CI
pkgradar gate --ecosystem pypi behemot-framework==0.5.5