PkgRadar

PyPI · pypi.org

icdev

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 1.2.29

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/data/validation_runner.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · icdev-1.2.29/icdev/tools/databridge/forge/sandbox_adapter.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/genesis/reflexes/govchain_anchor.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/security/agent_trust_scorer.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/security/mcp_tool_authorizer.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/security/prompt_injection_detector.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/security/tool_chain_validator.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · icdev-1.2.29/icdev/tools/studio/executors/validation_runner.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · icdev-1.2.29/icdev/tools/data/terraform_destroy.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · icdev-1.2.29/icdev/tools/data_canvas/csp.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · icdev-1.2.29/icdev/tools/infra_canvas/adapters/localstack_adapter.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · icdev-1.2.29/icdev/tools/studio/executors/_base.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.29High risk2182026-06-02
1.2.28High risk2182026-05-30

Block this in CI

PkgRadar gates icdev (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi icdev==1.2.29