Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 88
- Versions published
- 79
- First published
- Mar 2026
- Publisher
- reion
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@m5kdev/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@m5kdev/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Credential file access: matched "AWS_ACCESS_KEY"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 20 · status changed
Evidence
Static findings
4 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 4 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Credential file access | package/dist/src/modules/file/file.repository.cjs | matched "AWS_ACCESS_KEY" | 5 |
| low | Credential file access | package/dist/src/modules/notification/notification.providers.cjs | matched "GOOGLE_APPLICATION_CREDENTIALS" | 5 |
| low | Credential file access | package/dist/src/modules/file/file.repository.mjs | matched "AWS_ACCESS_KEY" | 5 |
| low | Credential file access | package/dist/src/modules/notification/notification.providers.mjs | matched "GOOGLE_APPLICATION_CREDENTIALS" | 5 |
Manifest
Package metadata
Scripts7
buildtsdowncheck-typestsc --noEmitlintbiome check .lint:fixbiome check . --writetestjest -c jest.config.tstest:watchjest -c jest.config.ts --watchversion:patchnpm version patch
Dependencies54
@aws-sdk/client-s33.891.0@aws-sdk/client-sts3.891.0@aws-sdk/s3-request-presigner3.891.0@libsql/client0.17.0@m5kdev/commons0.20.48@m5kdev/config0.20.48@mastra/core1.0.4@mastra/libsql1.0.0@mastra/rag2.0.0@openrouter/ai-sdk-provider2.9.0@parse/node-apn8.0.0@posthog/ai6.2.0@sentry/node10.22.0@trpc/server11.4.3@types/multer1.4.12ai6.0.191better-auth1.4.18bip324.0.0bip393.1.0bitcoinjs-lib7.0.0body-parser1.20.3bullmq5.58.0cors2.8.5dotenv16.6.1drizzle-orm0.44.3drizzle-zod0.8.2express4.21.2ffmpeg-ffprobe-static6.1.2-rc.1firebase-admin13.6.0ioredis5.7.0- …and 24 more.