PkgRadar

PyPI · pypi.org

crucible-security

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 0.5.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · crucible_security-0.5.0/crucible/attacks/multi_turn_strategies.py
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · crucible_security-0.5.0/crucible/attacks/exfiltration_kit.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · crucible_security-0.5.0/.venv_ci/Lib/site-packages/pip/_vendor/packaging/licenses/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · crucible_security-0.5.0/.venv_ci/Lib/site-packages/pip/_vendor/pkg_resources/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · crucible_security-0.5.0/.venv_test/Lib/site-packages/pip/_vendor/packaging/licenses/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · crucible_security-0.5.0/.venv_test/Lib/site-packages/pip/_vendor/pkg_resources/__init__.py
mediumRemote Payloadmatched "curl " · crucible_security-0.5.0/crucible/attacks/multi_agent_contagion.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0High risk1822026-06-03

Block this in CI

PkgRadar gates crucible-security (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi crucible-security==0.5.0