PkgRadar

PyPI · pypi.org

securityagent-core

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 4.31.0

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · securityagent_core-4.31.0/src/endpoint_agent/engine.py
highCredential file accessmatched ".ssh/" · securityagent_core-4.31.0/src/endpoint_agent/scanners/ml_classifier.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.31.0High risk902026-06-12
4.30.0High risk902026-06-01
4.29.0High risk902026-05-30
4.28.0High risk902026-05-30

Block this in CI

PkgRadar gates securityagent-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi securityagent-core==4.31.0