PkgRadar

PyPI · pypi.org

skcapstone

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 0.6.8

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · skcapstone-0.6.8/src/skcapstone/onboard.py
mediumRemote Payloadmatched "curl " · skcapstone-0.6.8/src/skcapstone/data/sk-agent-picker.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.8High risk422026-06-05

Block this in CI

PkgRadar gates skcapstone (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi skcapstone==0.6.8