PkgRadar

Package evidence

@specverse/[email protected]

Credential file access: matched ".aws"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@specverse/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@specverse/[email protected]"],"fail_on":"high"}'
Publishercainen
Artifact bytes1,259,894
Previous version3.5.0
Published2025-12-06T14:49:17.949Z
SHA-256da3f0ea7e83c43efa4dc18c0f13c79c5401d0228154734daa86f1f3b2b001e32

Why flagged

What the scanner saw

Credential file access: matched ".aws"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
57Score
3.5.1Version
Status history (1 event)
  1. newavailable · risk high · score 57 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

cainen

6 members · evidence strength 79

Evidence

Static findings

10 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspackage/prompts/core/standard/v5/realize.prompt.yamlmatched ".aws"30
Show all 10 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accesspackage/prompts/core/standard/v5/realize.prompt.yamlmatched ".aws"30
lowObfuscationpackage/scripts/maintenance/convert-library-yaml-to-v31.jsmatched "\\x1b"3
lowObfuscationpackage/dist/registry/formatters/error-formatter.jsmatched "\\x1b"3
lowObfuscationpackage/templates/backend-only/generated/code/integration-test.template.jsmatched "\\x1b"3
lowObfuscationpackage/templates/default/generated/code/integration-test.template.jsmatched "\\x1b"3
lowObfuscationpackage/templates/frontend-only/generated/code/integration-test.template.jsmatched "\\x1b"3
lowObfuscationpackage/templates/full-stack/generated/code/integration-test.template.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/test/run-all-tests.jsmatched "\\x1b"3
lowObfuscationpackage/dist/cli/specverse-cli.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/test/validate-all-specly.jsmatched "\\x1b"3

Manifest

Package metadata

Scripts32
  • _comment_generatedAfter realize:all, run 'test:generated:run' to set up the generated project
  • _comment_realizeUse 'realize:all' to generate complete runnable project (ORM, services, routes, scaffolding, main.ts)
  • buildnpm run validate && npm run infer
  • build:completenpm run validate && npm run infer && npm run infer:deployment && npm run generate:diagrams && npm run generate:docs
  • build:fullnpm run validate && npm run infer:deployment && npm run generate:diagrams
  • devnpm run validate && npm run infer
  • formatspecverse dev format specs/main.specly --write
  • generate:completenpm run infer && npm run infer:docs
  • generate:diagram:architecturespecverse gen diagram specs/main.specly -t model-architecture -o docs/diagrams/architecture.mmd
  • generate:diagram:deploymentspecverse gen diagram specs/main.specly -t deployment-topology -o docs/diagrams/deployment.mmd
  • generate:diagram:erspecverse gen diagram specs/main.specly -t er-diagram -o docs/diagrams/er-diagram.mmd
  • generate:diagram:event-flowspecverse gen diagram specs/main.specly -t event-flow-layered -o docs/diagrams/event-flow-layered.mmd
  • generate:diagram:lifecyclespecverse gen diagram specs/main.specly -t lifecycle -o docs/diagrams/lifecycle.mmd
  • generate:diagramsspecverse gen diagram specs/main.specly --output docs/diagrams
  • generate:docsspecverse gen docs specs/main.specly --output docs/main-docs.md
  • inferspecverse infer specs/main.specly -o generated/{{projectNameKebab}}-complete.specly
  • infer:deploymentspecverse infer specs/main.specly --deployment --environment development -o generated/{{projectNameKebab}}-deployed.specly
  • infer:deployment:docsspecverse gen docs generated/{{projectNameKebab}}-deployed.specly --output generated/docs/deployed-docs.md && specverse gen diagram generated/{{projectNameKebab}}-deployed.specly --output generated/docs/deployed-diagrams
  • infer:deployment:prodspecverse infer specs/main.specly --deployment --environment production -o generated/{{projectNameKebab}}-deployed-prod.specly
  • infer:deployment:prod:docsspecverse gen docs generated/{{projectNameKebab}}-deployed-prod.specly --output generated/docs/deployed-prod-docs.md && specverse gen diagram generated/{{projectNameKebab}}-deployed-prod.specly --output generated/docs/deployed-prod-diagrams
  • infer:docsspecverse gen docs generated/{{projectNameKebab}}-complete.specly --output generated/docs/complete-docs.md && specverse gen diagram generated/{{projectNameKebab}}-complete.specly --output generated/docs/complete-diagrams
  • processspecverse gen yaml specs/main.specly -o generated/{{projectNameKebab}}-processed.yaml
  • realize:allspecverse realize all specs/main.specly -m manifests/implementation.yaml -o generated/code
  • realize:ormspecverse realize orm specs/main.specly -m manifests/implementation.yaml
  • realize:routesspecverse realize routes specs/main.specly -m manifests/implementation.yaml
  • realize:servicesspecverse realize services specs/main.specly -m manifests/implementation.yaml
  • test./scripts/test-all.sh
  • test:generated:compilecd generated/code && npx tsc --noEmit --skipLibCheck 2>&1 || echo 'TypeScript compilation check (some errors expected without npm install)'
  • test:generated:runcd generated/code && npm install && npm run db:generate && echo 'Generated code is ready to run with: npm run dev'
  • validatespecverse validate specs/main.specly
  • …and 2 more.