PkgRadar

PyPI · pypi.org

gpustack-runner

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.26.post5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · gpustack_runner-0.1.26.post5/tools/chat.sh
mediumRemote Payloadmatched "curl " · gpustack_runner-0.1.26.post5/tools/chat_tool_get_temperature.sh
mediumRemote Payloadmatched "curl " · gpustack_runner-0.1.26.post5/tools/chat_tool_get_weather.sh
mediumRemote Payloadmatched "curl " · gpustack_runner-0.1.26.post5/tools/chat_tool_where_am_i.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.26.post5High risk332026-06-11
0.1.26.post4High risk332026-06-10
0.1.26.post3High risk332026-06-05
0.1.26.post2Review422026-05-27

Block this in CI

PkgRadar gates gpustack-runner (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi gpustack-runner==0.1.26.post5