Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 21
- First published
- Feb 2026
- Publisher
- lemonclown
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@guanghechen/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@guanghechen/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 4775605 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Large Javascript Payload | package/lib/esm/command-DvX8d5iO.mjs | 4775605 bytes | 0 |
Manifest
Package metadata
Scripts9
buildcross-env ROLLUP_OBFUSCATE=true rollup -c ../../rollup.config.mjsbuild:linkpnpm build && npm link --forcecleanrimraf libpublish:checknode script/check-publish-payload.mjsschema:checknode script/check-schema-drift.mjsschema:confignode script/gen-schema.mjsschema:dtsnode script/gen-schema-dts.mjstestvitest run --config ../../vitest.config.tstest:coveragevitest run --config ../../vitest.config.ts --coverage
Dependencies28
@guanghechen/commander4.8.0@guanghechen/reporter3.3.0@yozora/ast2.3.16@yozora/character2.3.16@yozora/core-parser2.3.16@yozora/core-tokenizer2.3.16@yozora/tokenizer-autolink2.3.16@yozora/tokenizer-autolink-extension2.3.16@yozora/tokenizer-break2.3.16@yozora/tokenizer-delete2.3.16@yozora/tokenizer-emphasis2.3.16@yozora/tokenizer-heading2.3.16@yozora/tokenizer-image2.3.16@yozora/tokenizer-inline-code2.3.16@yozora/tokenizer-link2.3.16@yozora/tokenizer-link-reference2.3.16@yozora/tokenizer-list2.3.16@yozora/tokenizer-paragraph2.3.16@yozora/tokenizer-setext-heading2.3.16@yozora/tokenizer-table2.3.16@yozora/tokenizer-text2.3.16@yozora/tokenizer-thematic-break2.3.16canvas3.2.3entities8.0.0image-size2.0.2jszip3.10.1pptxgenjs4.0.1ts-json-schema-generator2.9.0