PyPI · pypi.org
workweaver
Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.
Why PkgRadar flagged 0.1.12
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('os') — reflection bypass for static checks. · workweaver-0.1.12/apps/backend/managed_lambda_handler.py |
| high | Credential file access | matched "aws_secret_access_key" · workweaver-0.1.12/apps/backend/services/inference/sync_bridge.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · workweaver-0.1.12/apps/backend/providers/secret_provider.py |
| medium | Credential file access | matched "aws_access_key" · workweaver-0.1.12/apps/backend/services/inference/bedrock_client.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · workweaver-0.1.12/apps/backend/voice_services/xai_relay_service.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.12 | High risk | 130 | 2026-06-02 |
Block this in CI
pkgradar gate --ecosystem pypi workweaver==0.1.12