PkgRadar

PyPI · pypi.org

claude-ns-hub

Py Runtime Dynamic Dangerous Import: Dynamic __import__('subprocess') — reflection bypass for static checks.

Why PkgRadar flagged 0.2.25

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('subprocess') — reflection bypass for static checks. · hub/server.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · hub/server.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.25High risk652026-06-08
0.2.26High risk952026-06-08
0.2.24High risk652026-06-07
0.2.23High risk652026-06-07
0.2.22High risk652026-06-07
0.2.21High risk652026-06-07
0.2.20High risk652026-06-07
0.2.19High risk652026-06-07
0.2.18High risk652026-06-02
0.2.17High risk652026-06-02
0.2.16High risk352026-06-02
0.2.15High risk352026-06-02
0.2.14High risk352026-05-30
0.2.13High risk352026-05-30
0.2.12High risk352026-05-30
0.2.11High risk352026-05-30

Block this in CI

PkgRadar gates claude-ns-hub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi claude-ns-hub==0.2.25