PkgRadar

Package evidence

@circuitwall/[email protected]

Remote Payload, Credential file access, Install-time lifecycle script +1 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
2,105Niche · −30% score
Versions published
33
First published
May 2026
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@circuitwall/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@circuitwall/[email protected]"],"fail_on":"review"}'
Artifact bytes47,473,558
Previous version1.13.2
Published2026-06-19T18:35:37.268Z
SHA-25684087a5fd47f4c35e27a44ee339d0d1d94fd1f24e466a7be1ded50472756c5c5

Why flagged

What the scanner saw

New Lifecycle Script Vs Previous

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
119Score
1.14.1Version
Status history (1 event)
  1. newavailable · risk review · score 119 · status changed

Evidence

Static findings

13 static · 1 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highNew Lifecycle Script Vs Previousmanifest40
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
Show all 14 findings (low-signal and informational)
SeverityKindPathDetailPoints
highNew Lifecycle Script Vs Previousmanifest40
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowInstall-time lifecycle scriptmanifest5

Manifest

Package metadata

Dependencies34
  • @anthropic-ai/sdk^0.104.2
  • @circuitwall/atlassian-langchain^1.0.0
  • @circuitwall/github-langchain^1.0.0
  • @circuitwall/jira-align-langchain^1.0.0
  • @circuitwall/ms-todo-langchain^0.1.0
  • @langchain/cohere^1.0.5
  • @langchain/core^1.1.46
  • @langchain/deepseek^1.0.25
  • @langchain/google-genai^2.1.30
  • @langchain/langgraph^1.3.0
  • @langchain/langgraph-checkpoint^1.0.2
  • @langchain/mcp-adapters^1.1.3
  • @tailwindcss/postcss^4.3.0
  • @whiskeysockets/baileys^7.0.0-rc13
  • autoprefixer^10.5.0
  • cron-parser^5.5.0
  • cross-spawn^7.0.6
  • highlight.js^11.11.1
  • lucide-react^1.16.0
  • next^16.2.6
  • openai^6.38.0
  • postcss^8.5.14
  • qrcode^1.5.4
  • react^19.2.6
  • react-dom^19.2.6
  • react-markdown^10.1.0
  • rehype-highlight^7.0.2
  • rehype-raw^7.0.0
  • rehype-sanitize^6.0.0
  • remark-gfm^4.0.1
  • …and 4 more.
Optional dependencies1
  • @napi-rs/keyring^1.3.0