PkgRadar

PyPI · pypi.org

cluxion-os

Remote Payload: matched "curl "

Why PkgRadar flagged 1.0.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · cluxion_os-1.0.1/src/cluxion_os/cli/bootstrap_deps.py
mediumCredential file accessmatched "GITHUB_TOKEN" · cluxion_os-1.0.1/src/cluxion_os/integrations/token_direct/github.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0Review522026-06-07
1.0.3Review522026-05-30
1.0.1High risk722026-05-29
1.0.0High risk822026-05-29

Block this in CI

PkgRadar gates cluxion-os (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi cluxion-os==1.0.1
cluxion-os — PyPI security scan | PkgRadar