PyPI · pypi.org
cheetahclaws
Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.
Why PkgRadar flagged 3.5.82
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('sys') — reflection bypass for static checks. · cheetahclaws-3.5.82/bridges/wechat.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · cheetahclaws-3.5.82/modular/video/tts.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.5.82 | High risk | 65 | 2026-06-05 |
3.5.81 | High risk | 65 | 2026-06-05 |
Block this in CI
pkgradar gate --ecosystem pypi cheetahclaws==3.5.82