PkgRadar

PyPI · pypi.org

vibe-seller

Remote Payload: matched "curl "

Why PkgRadar flagged 0.0.6

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · vibe_seller-0.0.6/docker/docker-entrypoint.sh
mediumRemote Payloadmatched "curl " · vibe_seller-0.0.6/start.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.6Review242026-05-29

Block this in CI

PkgRadar gates vibe-seller (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi vibe-seller==0.0.6