Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 299
- Versions published
- 77
- First published
- Jan 2026
- Publisher
- tjwp
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@in-the-loop-labs/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@in-the-loop-labs/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts12
changesetchangesetdevnode bin/pair-review.jsgenerate:skill-promptsnode scripts/generate-skill-prompts.jsreleasenpm whoami > /dev/null || { echo 'Error: Not logged in to npm. Run: npm login'; exit 1; } && pnpm run version && changeset tag && npm publish && git push && git push --tagsstartnode src/server.jstestvitest runtest:coveragevitest run --coveragetest:e2eplaywright testtest:e2e:debugplaywright test --debugtest:e2e:headedplaywright test --headedtest:watchvitestversionchangeset version && pnpm install --lockfile-only && bash scripts/generate-package-lock.sh && node scripts/sync-plugin-versions.js && git add package.json pnpm-lock.yaml package-lock.json CHANGELOG.md .changeset .claude-plugin/marketplace.json plugin/.claude-plugin/plugin.json plugin-code-critic/.claude-plugin/plugin.json && git commit -m "RELEASING: v$(node -p "require('./package.json').version")"
Dependencies14
@agentclientprotocol/sdk^0.14.1@modelcontextprotocol/sdk^1.25.3@octokit/rest^19.0.11better-sqlite3^11.8.1express^4.18.2glob^13.0.6markdown-it^13.0.2open^9.1.0semver^7.7.4simple-git^3.19.1update-notifier^5.1.0uuid^11.1.0ws^8.19.0zod^4.3.6