PkgRadar

PyPI · pypi.org

glyphh

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 2.6.7

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · glyphh-2.6.7/capabilities/code/commands.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · glyphh-2.6.7/capabilities/voice/encoder.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.7High risk602026-06-02

Block this in CI

PkgRadar gates glyphh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi glyphh==2.6.7