PkgRadar

RubyGems · rubygems.org

workos

Rb Install Time Backticks: Backtick subshell or %x() shell-out — runs shell with interpolated input.

Why PkgRadar flagged 9.0.0

SeveritySignalEvidence
highRb Install Time BackticksBacktick subshell or %x() shell-out — runs shell with interpolated input. · workos.gemspec
highRb Runtime Base64 DecodeBase64.decode64 combined with eval/system — classic obfuscated payload. · lib/workos/encryptors/aes_gcm.rb
highRb Runtime Base64 DecodeBase64.decode64 combined with eval/system — classic obfuscated payload. · lib/workos/vault.rb

Scanned versions

VersionVerdictScoreScanned (UTC)
9.0.0Review302026-05-26

Block this in CI

PkgRadar gates workos (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]