PkgRadar

PyPI · pypi.org

claudia-agent

Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 1.44.0

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · claudia_agent-1.44.0/src/claudia/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · claudia_agent-1.44.0/src/claudia/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.44.0Review802026-06-09
1.43.0Review802026-06-09
1.42.0Review802026-06-09
1.41.0Review802026-06-09
1.40.0Low risk02026-06-07
1.39.0Low risk02026-06-07
1.38.0Low risk02026-06-07
1.37.0Low risk02026-06-06
1.36.0Low risk02026-06-06
1.35.0Low risk02026-06-06
1.34.0Low risk02026-06-06
1.33.0Low risk02026-06-04
1.32.0Low risk02026-06-04
1.31.0Low risk02026-06-04
1.30.0Low risk02026-06-04
1.29.0Low risk02026-06-04
1.28.0Low risk02026-06-04
1.27.0Low risk02026-06-03
1.26.0Low risk02026-06-03
1.25.0Low risk02026-06-03
1.24.0Low risk02026-06-02
1.23.0Low risk02026-06-02
1.22.0Low risk02026-06-02
1.21.0Low risk02026-06-02
1.20.0Low risk02026-06-01

Block this in CI

PkgRadar gates claudia-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi claudia-agent==1.44.0