PkgRadar

PyPI · pypi.org

inspect-evals

DNS / OAST exfiltration: matched "burpcollaborator.net"

Why PkgRadar flagged 0.14.0

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · inspect_evals-0.14.0/src/inspect_evals/cyberseceval_4/threat_intel_reasoning/report_questions.json
mediumRemote Payloadmatched "curl " · inspect_evals-0.14.0/src/inspect_evals/agentdojo/data/suites/workspace_plus/terminal/mock-gist-server/gist.github.com/bsptech/389024167213dae90b5a7483f9fd81d5/raw/bde28851c49777d31581f8b7078e2b96/diagnostic.sh
mediumRemote Payloadmatched "wget " · inspect_evals-0.14.0/src/inspect_evals/cybench/challenges/back_to_the_past/solution/solution.sh
mediumRemote Payloadmatched "curl " · inspect_evals-0.14.0/src/inspect_evals/cybench/challenges/eval_me/resources/extract.sh
mediumRemote Payloadmatched "wget " · inspect_evals-0.14.0/src/inspect_evals/cybench/challenges/flag_command/solution/solution.sh
mediumRemote Payloadmatched "wget " · inspect_evals-0.14.0/src/inspect_evals/cybench/challenges/it_has_begun/resources/script.sh
mediumRemote Payloadmatched "curl " · inspect_evals-0.14.0/src/inspect_evals/cybench/challenges/labyrinth_linguist/solution/flag.sh
mediumRemote Payloadmatched "curl " · inspect_evals-0.14.0/src/inspect_evals/threecb/task_configs/impact_defacing/watcher.sh
mediumRemote Payloadmatched "curl " · inspect_evals-0.14.0/src/inspect_evals/threecb/task_configs/initialaccess_mail_link/watcher.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.14.0High risk922026-06-11
0.13.2High risk922026-06-04
0.13.1High risk922026-05-30

Block this in CI

PkgRadar gates inspect-evals (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi inspect-evals==0.14.0