PkgRadar

PyPI · pypi.org

thruk-mcp

Remote Payload: matched "curl "

Why PkgRadar flagged 1.6.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · thruk_mcp-1.6.0/.github/workflows/integration.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.10.1Low risk02026-06-11
1.10.0Low risk02026-06-11
1.9.0Low risk02026-06-10
1.8.0Low risk02026-05-31
1.7.1Low risk02026-05-30
1.7.0Low risk02026-05-30
1.6.1Low risk02026-05-28
1.6.0Review152026-05-27

Block this in CI

PkgRadar gates thruk-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi thruk-mcp==1.6.0