PkgRadar

PyPI · pypi.org

xllamacpp

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2026.6.9538

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · xllamacpp-2026.6.9538/setup.py
highCredential File Packagedxllamacpp-2026.6.9538/thirdparty/llama.cpp/tools/ui/.npmrc · xllamacpp-2026.6.9538/thirdparty/llama.cpp/tools/ui/.npmrc

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9538High risk422026-06-07

Block this in CI

PkgRadar gates xllamacpp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi xllamacpp==2026.6.9538