PkgRadar

Package evidence

@squadbase/[email protected]

Credential file access: matched "AWS_ACCESS_KEY"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
119
First published
Mar 2026
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@squadbase/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@squadbase/[email protected]"],"fail_on":"review"}'
Artifact bytes2,392,032
Previous version0.1.17-dev.423ee34
Published2026-06-08T08:34:50.367Z
SHA-2560fbe8c5371d16e2858882c8aed2104262ff14bae9b2182625f8748646b7b4c08

Why flagged

What the scanner saw

Credential file access: matched "AWS_ACCESS_KEY"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
1Score
0.1.17-dev.71a85cdVersion
Status history (1 event)
  1. newavailable · risk review · score 1 · status changed

Evidence

Static findings

73 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 73 findings (low-signal and informational)

Showing 60 of 73 findings.

SeverityKindPathDetailPoints
lowCredential file accesspackage/dist/connectors/aws-billing.jsmatched "AWS_ACCESS_KEY"5
lowObfuscation Densitypackage/dist/connectors/airtable-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/airtable.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/amplitude.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/asana.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/attio.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/aws-billing.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/azure-sql.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/backlog-api-key.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/clickup.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/cosmosdb.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/customerio.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/dbt.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/freshdesk.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/freshsales.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/freshservice.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/gamma.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/github.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/gmail-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/gmail.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-ads.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-analytics-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-analytics.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-audit-log.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-calendar-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-calendar.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-docs.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-drive.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-search-console-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-sheets.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/google-slides.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/grafana.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/hubspot-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/hubspot.jshigh encoded/escaped-token density0
lowLarge Javascript Payloadpackage/dist/cli/index.js2154826 bytes0
lowLarge Javascript Payloadpackage/dist/index.js2178001 bytes0
lowObfuscation Densitypackage/dist/connectors/influxdb.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/intercom-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/intercom.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/jdbc.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/jira-api-key.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/kintone-api-token.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/kintone.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/linear.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/linkedin-ads.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/mailchimp-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/mailchimp.jshigh encoded/escaped-token density0
lowLarge Javascript Payloadpackage/dist/main.js2166703 bytes0
lowObfuscation Densitypackage/dist/connectors/meta-ads-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/meta-ads.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/mixpanel.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/monday.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/mongodb.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/notion-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/notion.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/oracle.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/outlook-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/powerbi-oauth.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/salesforce.jshigh encoded/escaped-token density0
lowObfuscation Densitypackage/dist/connectors/semrush.jshigh encoded/escaped-token density0

Manifest

Package metadata

Scripts4
  • buildtsup && npm run build:cli
  • build:clitsup src/cli/index.ts --out-dir dist/cli --format esm --platform node --no-splitting --external pg --external snowflake-sdk --external @google-cloud/bigquery --external mysql2 --external mssql --external oracledb --external ssh2 --external mongodb --external @azure/cosmos --external @aws-sdk/client-athena --external @aws-sdk/client-cost-explorer --external @aws-sdk/client-redshift-data --external @databricks/sql --external @clickhouse/client --external @google-analytics/data --external @kintone/rest-api-client --external hono --external @clack/prompts
  • clitsx src/cli/index.ts
  • type-checktsc
Dependencies22
  • @aws-sdk/client-athena^3.750.0
  • @aws-sdk/client-cost-explorer^3.750.0
  • @aws-sdk/client-redshift-data^3.750.0
  • @azure/cosmos^4.9.3
  • @clickhouse/client^1.18.2
  • @databricks/sql^1.8.0
  • @google-analytics/data^4.8.0
  • @google-cloud/bigquery^7.9.4
  • @hono/node-server^1.19.9
  • @hono/vite-build^1.10.0
  • @hono/vite-dev-server^0.25.0
  • @kintone/rest-api-client^5.5.0
  • google-auth-library^9.15.1
  • hono^4.11.9
  • mongodb^7.1.1
  • mssql^11.0.1
  • mysql2^3.11.0
  • oracledb^6.6.0
  • pg^8.18.0
  • snowflake-sdk^1.15.0
  • ssh2^1.16.0
  • zod^4.3.6