Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 570
- Versions published
- 180
- First published
- Feb 2026
- Publisher
- waydelyle
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@swarmclawai/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@swarmclawai/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Credential file access: matched ".ssh/"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 10 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Credential file access | package/src/lib/server/session-tools/index.ts | matched ".ssh/" | 5 |
| low | Install-time lifecycle script | package.json | postinstall="node ./scripts/postinstall.mjs" | 5 |
Manifest
Package metadata
Scripts39
benchmark:agent-regressionnode --import tsx ./scripts/run-agent-regression-suite.tsbenchmark:autonomynode ./scripts/benchmark-autonomy-harness.mjsbuildnode ./scripts/run-next-build.mjsbuild:ciNEXT_DISABLE_ESLINT=1 node ./scripts/run-next-build.mjsclinode ./bin/swarmclaw.jsdevnext dev --turbopack --hostname 0.0.0.0 -p 3456dev:cleanrm -rf .next && next dev --turbopack --hostname 0.0.0.0 -p 3456dev:webpacknext dev --webpack --hostname 0.0.0.0 -p 3456electron:buildnode ./scripts/build-electron.mjselectron:build:linuxnode ./scripts/build-electron.mjs --linuxelectron:build:macnode ./scripts/build-electron.mjs --macelectron:build:publishnode ./scripts/build-electron.mjs --publishelectron:build:winnode ./scripts/build-electron.mjs --winelectron:compiletsc -p electron/tsconfig.jsonelectron:devnpm run electron:compile && electron electron-dist/main.jsformateslint --fixlinteslintlint:baselinenode ./scripts/lint-baseline.mjs checklint:baseline:updatenode ./scripts/lint-baseline.mjs updatelint:fixeslint --fixpostinstallnode ./scripts/postinstall.mjsprepacknpm run build:ciquickstartnode ./scripts/easy-setup.mjs --startquickstart:prodnode ./scripts/easy-setup.mjs --prodsandbox:build:browserdocker build -f Dockerfile.sandbox-browser -t swarmclaw-sandbox-browser:bookworm-slim .setup:easynode ./scripts/easy-setup.mjsstartnode .next/standalone/server.jsstart:standalonenode .next/standalone/server.jstestnpm run test:cli && npm run test:setup && npm run test:openclaw && npm run test:runtime && npm run test:buildertest:buildertsx --test src/features/protocols/builder/utils/builder-template-access.test.ts src/features/protocols/builder/utils/nodes-to-template.test.ts src/features/protocols/builder/utils/template-to-nodes.test.ts src/features/protocols/builder/validators/dag-validator.test.ts- …and 9 more.
Dependencies76
@huggingface/transformers^3.8.1@langchain/anthropic^1.3.18@langchain/core^1.1.31@langchain/langgraph^1.2.2@langchain/openai^1.2.8@modelcontextprotocol/sdk^1.29.0@multiavatar/multiavatar^1.0.7@opentelemetry/api^1.9.1@opentelemetry/exporter-trace-otlp-http^0.214.0@opentelemetry/sdk-node^0.214.0@playwright/mcp^0.0.68@slack/bolt^4.6.0@swarmdock/sdk^0.5.3@tailwindcss/postcss^4@tanstack/react-query^5.91.0@types/better-sqlite3^7.6.13@types/dagre^0.7.54@types/mailparser^3.4.6@types/mime-types^2.1.4@types/node^20@types/nodemailer^7.0.11@types/qrcode^1.5.6@types/react^19@types/react-dom^19@types/ws^8.18.1@whiskeysockets/baileys^7.0.0-rc.9@xyflow/react^12.10.2@xyflow/system^0.0.76better-sqlite3^12.6.2bs58^5.0.0- …and 46 more.
Optional dependencies5
botbuilder^4.23.3googleapis^171.4.0matrix-bot-sdk^0.8.0opusscript0.0.8utf-8-validate5.0.10