PkgRadar

PyPI · pypi.org

contrast-agent

Py Import Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 11.4.0

SeveritySignalEvidence
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · contrast_agent-11.4.0/src/contrast_rewriter/__init__.py
mediumRemote Payloadmatched "curl " · contrast_agent-11.4.0/src/contrast_vendor/urllib3/fields.py

Scanned versions

VersionVerdictScoreScanned (UTC)
11.4.0Review102026-05-27

Block this in CI

PkgRadar gates contrast-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi contrast-agent==11.4.0