PkgRadar

PyPI · pypi.org

neo-cortex-mcp

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 6.1.0a8

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · neo_cortex_mcp-6.1.0a8/src/neo_cortex/core/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
6.1.0a17Review502026-06-03
6.1.0a16Review502026-06-02
6.1.0a15Review502026-06-02
6.1.0a14Review502026-06-02
6.1.0a13Review502026-06-02
6.1.0a12Review502026-06-02
6.1.0a11Review502026-05-30
6.1.0a10Review502026-05-30
6.1.0a9Review502026-05-30
6.1.0a8High risk502026-05-28
6.1.0a7High risk502026-05-28
6.1.0a6High risk502026-05-28
6.1.0a5High risk502026-05-28
6.1.0a4High risk502026-05-28
6.1.0a3High risk502026-05-28
6.1.0a2High risk502026-05-28
6.1.0High risk502026-05-28
6.0.0Low risk02026-05-27

Block this in CI

PkgRadar gates neo-cortex-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi neo-cortex-mcp==6.1.0a8