PkgRadar

PyPI · pypi.org

mahavishnu

Credential file access: matched "aws_secret_access_key"

Why PkgRadar flagged 0.7.2

SeveritySignalEvidence
highCredential file accessmatched "aws_secret_access_key" · mahavishnu-0.7.2/mahavishnu/core/code_index/signature_redaction.py
mediumRemote Payloadmatched "curl " · mahavishnu-0.7.2/config/clients/diagnose.sh
mediumRemote Payloadmatched "curl " · mahavishnu-0.7.2/config/clients/quickstart.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.2High risk542026-06-08

Block this in CI

PkgRadar gates mahavishnu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mahavishnu==0.7.2
mahavishnu — PyPI security scan | PkgRadar