PkgRadar

PyPI · pypi.org

mujoco-usd-converter

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · mujoco_usd_converter-0.3.0/build.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0Review82026-06-05

Block this in CI

PkgRadar gates mujoco-usd-converter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mujoco-usd-converter==0.3.0