PkgRadar

PyPI · pypi.org

inscript-lang

Py Runtime Dynamic Dangerous Import: Dynamic __import__('sys') — reflection bypass for static checks.

Why PkgRadar flagged 3.0.0

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · inscript_lang-3.0.0/interpreter.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · inscript_lang-3.0.0/interpreter.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · inscript_lang-3.0.0/stdlib.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0High risk802026-05-30
2.13.0High risk802026-05-30
2.10.0High risk802026-05-30
2.11.0High risk802026-05-30
2.12.0High risk802026-05-30
2.8.0High risk802026-05-30

Block this in CI

PkgRadar gates inscript-lang (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi inscript-lang==3.0.0