PyPI · pypi.org
quoin
Remote Payload: matched "curl "
Why PkgRadar flagged 0.9.22
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · quoin-0.9.22/quoin/tools/agentdesk/setup-agentdesk.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.9.22 | Review | 12 | 2026-06-16 |
0.9.19 | Review | 12 | 2026-06-15 |
0.9.14 | Review | 12 | 2026-06-13 |
0.9.13 | Review | 12 | 2026-06-12 |
0.9.12 | Review | 12 | 2026-06-12 |
0.9.11 | Review | 12 | 2026-06-12 |
0.9.10 | Review | 12 | 2026-06-12 |
0.9.6 | Review | 12 | 2026-06-08 |
0.9.3 | Review | 12 | 2026-06-07 |
0.9.0 | Review | 12 | 2026-06-06 |
0.7.2 | Review | 12 | 2026-06-04 |
0.6.0 | Review | 12 | 2026-05-30 |
0.5.18 | Low risk | 0 | 2026-05-30 |
0.5.16 | Low risk | 0 | 2026-05-29 |
0.5.15 | Low risk | 0 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem pypi quoin==0.9.22