PkgRadar

Package evidence

@agenit/[email protected]

Credential file access, Remote Payload, Large Javascript Payload +1 more

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@agenit/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@agenit/[email protected]"],"fail_on":"high"}'
Artifact bytes3,984,015
Previous version3.0.1
Published2026-05-23T13:47:35.211Z
SHA-25619474e669bb30715ab373832ee526cadc1d0824c4154802c3e2fba80b4a56b4f

Why flagged

What the scanner saw

Credential file access

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
235Score
3.2.3Version
Status history (1 event)
  1. newavailable · risk high · score 235 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPactive

Credential file access

693 members · evidence strength 90
Publisher / release actor burststale

Publisher burst: mohamedeldabaa

2 members · evidence strength 64
Repeated static TTPcandidate

Credential file access

693 members · max score 165

Evidence

Static findings

19 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accessmanifest30
highCredential file accessmanifest30
highCredential file accessmanifest30
highCredential file accessmanifest30
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumLarge Javascript Payloadmanifest10
Show all 19 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accessmanifest30
highCredential file accessmanifest30
highCredential file accessmanifest30
highCredential file accessmanifest30
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumLarge Javascript Payloadmanifest10
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3

Manifest

Package metadata

Dependencies18
  • @google/gemini-cli>=0.37.0
  • @iarna/toml^2.2.5
  • @opentelemetry/api^1.9.0
  • @opentelemetry/exporter-metrics-otlp-http^0.57.0
  • @opentelemetry/exporter-trace-otlp-http^0.57.0
  • @opentelemetry/resources^1.30.0
  • @opentelemetry/sdk-metrics^1.30.0
  • @opentelemetry/sdk-trace-base^1.30.0
  • @opentelemetry/sdk-trace-node^1.30.0
  • @opentelemetry/semantic-conventions^1.28.0
  • chalk^5.3.0
  • ink^5.1.0
  • ink-spinner^5.0.0
  • ink-text-input^6.0.0
  • jose^6.2.3
  • openid-client^6.8.4
  • react^18.3.1
  • yargs^17.7.2