PkgRadar

PyPI · pypi.org

tm-ai

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2.91.15

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · tm_ai-2.91.15/cvc/agent/_vendor/hermes/hermes_cli/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · tm_ai-2.91.15/cvc/bundled_skills/productivity/google-workspace/scripts/setup.py
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · tm_ai-2.91.15/cvc/bundled_skills/productivity/google-workspace/scripts/setup.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · tm_ai-2.91.15/cvc/agent/_vendor/hermes/hermes_cli/clipboard.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · tm_ai-2.91.15/cvc/agent/_vendor/hermes/tools/tts_tool.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · tm_ai-2.91.15/cvc/bundled_skills/productivity/google-workspace/scripts/google_api.py
mediumRemote Payloadmatched "curl " · tm_ai-2.91.15/cvc/agent/_vendor/hermes/hermes_cli/memory_setup.py
mediumRemote Payloadmatched "github.com/KittenML/KittenTTS/releases/download" · tm_ai-2.91.15/cvc/agent/_vendor/hermes/hermes_cli/setup.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · tm_ai-2.91.15/cvc/agent/_vendor/hermes/hermes_cli/model_switch.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.91.15High risk2152026-06-05

Block this in CI

PkgRadar gates tm-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi tm-ai==2.91.15