PkgRadar

PyPI · pypi.org

unplug-ai

Credential file access: matched ".ssh/"

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highCredential file accessmatched ".ssh/" · unplug_ai-0.3.0/src/unplug/core/toolchain.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk352026-06-12
0.2.3High risk352026-06-12
0.2.2High risk352026-06-12
0.2.1High risk352026-06-11
0.2.0High risk352026-06-11
0.1.0Review102026-05-28

Block this in CI

PkgRadar gates unplug-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi unplug-ai==0.3.0