Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 446
- Versions published
- 38
- First published
- Feb 2026
- Publisher
- kfromlarkit
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@embarkai/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@embarkai/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "cUrl "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 24 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/dist/index.cjs | matched "cUrl " | 12 |
| medium | Remote Payload | package/dist/index.js | matched "cUrl " | 12 |
Manifest
Package metadata
Scripts9
buildpnpm build:css && tsup && pnpm build:iframe-html && pnpm build:copy-cssbuild:copy-cssnode scripts/copy-styles-css.jsbuild:csstailwindcss -c tailwind.config.cjs -i src/styles/index.css -o src/styles/built.css --minifybuild:iframe-htmlnode scripts/copy-iframe-html.jscleanrm -rf distcsvnpx tsx src/i18n/utils/prepareCsvProofread.ts --origin en --target zhdevpnpm build:css && tsup --watchdev:iframevite --config iframe/vite.config.tslocalenpx tsx src/i18n/utils/proofreadLocale.ts
Dependencies18
@embarkai/core0.3.4@radix-ui/react-checkbox>=1.3.3@radix-ui/react-dialog>=1.1.15@radix-ui/react-select>=2.2.6@radix-ui/react-slot>=1.2.4@rainbow-me/rainbowkit^2.2.10@sentry/browser^10.22.0class-variance-authority^0.7.0clsx^2.1.1dayjs^1.11.9dkls23-wasm^0.1.0framer-motion^12.23.24lodash-es^4.17.21lucide-react^0.454.0qrcode^1.5.0viem^2.38.0wagmi^2.17.5zustand^5.0.8