Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 14
- First published
- Jun 2026
- Publisher
- aaron_toto
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@bitseek/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@bitseek/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts16
checkfind ./bin ./src ./test/compose/scripts \( -name '*.js' -o -name '*.mjs' \) -print0 | xargs -0 -n1 node --checkpack:dry-runnpm pack --dry-runprepublishOnlynpm run release:checkrelease:checknpm run check && npm run pack:dry-runstartnode ./bin/hermes-agent-pack.jstestnpm run check && npm run test:wizardtest:compose:bootstrapdocker compose -f test/compose/compose.yaml run --build --rm fake-bootstraptest:compose:e2ebash test/compose/scripts/prepare-official-fixtures.sh && docker compose -f test/compose/compose.yaml run --build --rm official-e2etest:compose:e2e:livebash test/compose/scripts/prepare-official-fixtures.sh && docker compose -f test/compose/compose.yaml run --build --rm official-e2e-livetest:compose:fulldocker compose -f test/compose/compose.yaml run --build --rm fresh-linuxtest:compose:npm-default-pack:livedocker compose -f test/compose/compose.yaml run --build --rm npm-default-pack-livetest:compose:officialbash test/compose/scripts/prepare-official-fixtures.sh && docker compose -f test/compose/compose.yaml run --build --rm official-installertest:compose:smokedocker compose -f test/compose/compose.yaml run --build --rm node-linuxtest:compose:webui-chat:livedocker compose -f test/compose/compose.yaml run --build --rm official-webui-chat-livetest:provider:livebash test/compose/scripts/run-provider-live-flow.shtest:wizardbash test/compose/scripts/run-wizard-flow.sh
Dependencies2
semver^7.7.1yaml^2.7.0