PkgRadar

Package evidence

@symerian/[email protected]

Large Javascript Payload: 2223064 bytes

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
681
Versions published
236
First published
Feb 2026
Publisher
symerian

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@symerian/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@symerian/[email protected]"],"fail_on":"review"}'
Publishersymerian
Artifact bytes7,243,483
Previous version3.5.31
Published2026-05-25T15:51:47.700Z
SHA-256c3897f39f624d83bd98b56802a870d9210476bf9165b7c28d32793709c652311

Why flagged

What the scanner saw

Large Javascript Payload: 2223064 bytes

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
75Score
3.5.32Version
Status history (1 event)
  1. newavailable · risk review · score 75 · status changed

Evidence

Static findings

13 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/dist/pi-embedded-V-5MAZNb.js2223064 bytes10
mediumLarge Javascript Payloadpackage/dist/unified-runner-C7BRCFJF.js2225037 bytes10
Show all 13 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/dist/pi-embedded-V-5MAZNb.js2223064 bytes10
mediumLarge Javascript Payloadpackage/dist/unified-runner-C7BRCFJF.js2225037 bytes10
lowCredential file accesspackage/dist/manager-DM2oPS8M.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/dist/manager-NDn8AFhr.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/dist/model-auth-1EAQvYRv.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/dist/model-auth-Byr7Gic_.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/dist/models-config-B5Xxy-c-.jsmatched "GITHUB_TOKEN"5
lowCredential file accesspackage/dist/models-config-CiR_RUxw.jsmatched "GITHUB_TOKEN"5
lowCredential file accesspackage/dist/onboard-custom-BcRYreNG.jsmatched ".azure"5
lowCredential file accesspackage/dist/onboard-custom-CfKvdcJ5.jsmatched ".azure"5
lowCredential file accesspackage/dist/server-methods-6-10RyMD.jsmatched ".ssh"5
lowCredential file accesspackage/dist/server-methods-Bdz-OwQ4.jsmatched ".ssh"5
lowCredential file accesspackage/extensions/msteams/src/attachments.test.tsmatched ".azure"5

Manifest

Package metadata

Scripts85
  • android:assemblecd apps/android && ./gradlew :app:assembleDebug
  • android:installcd apps/android && ./gradlew :app:installDebug
  • android:runcd apps/android && ./gradlew :app:installDebug && adb shell am start -n ai.symi.android/.MainActivity
  • android:testcd apps/android && ./gradlew :app:testDebugUnitTest
  • buildpnpm canvas:a2ui:bundle && tsdown && pnpm build:plugin-sdk:dts && node --import tsx scripts/write-plugin-sdk-entry-dts.ts && node --import tsx scripts/canvas-a2ui-copy.ts && node --import tsx scripts/copy-hook-metadata.ts && node --import tsx scripts/copy-export-html-templates.ts && node --import tsx scripts/write-build-info.ts && pnpm ui:build
  • build:plugin-sdk:dtstsc -p tsconfig.plugin-sdk.dts.json
  • canvas:a2ui:bundlebash scripts/bundle-a2ui.sh
  • checkpnpm format:check && pnpm tsgo && pnpm lint
  • check:docspnpm format:docs:check && pnpm lint:docs && pnpm docs:check-links
  • check:locnode --import tsx scripts/check-ts-max-loc.ts --max 500
  • deadcode:cipnpm deadcode:report:ci:knip && pnpm deadcode:report:ci:ts-prune && pnpm deadcode:report:ci:ts-unused
  • deadcode:knippnpm dlx knip --no-progress
  • deadcode:reportpnpm deadcode:knip; pnpm deadcode:ts-prune; pnpm deadcode:ts-unused
  • deadcode:report:ci:knipmkdir -p .artifacts/deadcode && pnpm deadcode:knip > .artifacts/deadcode/knip.txt 2>&1 || true
  • deadcode:report:ci:ts-prunemkdir -p .artifacts/deadcode && pnpm deadcode:ts-prune > .artifacts/deadcode/ts-prune.txt 2>&1 || true
  • deadcode:report:ci:ts-unusedmkdir -p .artifacts/deadcode && pnpm deadcode:ts-unused > .artifacts/deadcode/ts-unused-exports.txt 2>&1 || true
  • deadcode:ts-prunepnpm dlx ts-prune src extensions scripts
  • deadcode:ts-unusedpnpm dlx ts-unused-exports tsconfig.json --ignoreTestFiles --exitWithCount
  • devnode scripts/run-node.mjs
  • docs:binnode scripts/build-docs-list.mjs
  • docs:check-linksnode scripts/docs-link-audit.mjs
  • docs:devcd docs && mint dev
  • docs:listnode scripts/docs-list.js
  • docs:spellcheckbash scripts/docs-spellcheck.sh
  • docs:spellcheck:fixbash scripts/docs-spellcheck.sh --write
  • formatoxfmt --write
  • format:allpnpm format && pnpm format:swift
  • format:checkoxfmt --check
  • format:diffoxfmt --write && git --no-pager diff
  • format:docsgit ls-files 'docs/**/*.md' 'docs/**/*.mdx' 'README.md' | xargs oxfmt --write
  • …and 55 more.
Dependencies48
  • @agentclientprotocol/sdk0.14.1
  • @aws-sdk/client-bedrock^3.995.0
  • @buape/carbon0.0.0-beta-20260216184201
  • @clack/prompts^1.0.1
  • @homebridge/ciao^1.3.5
  • @lydell/node-pty1.2.0-beta.3
  • @mariozechner/pi-agent-core0.54.0
  • @mariozechner/pi-ai0.54.0
  • @mariozechner/pi-coding-agent0.54.0
  • @mariozechner/pi-tui0.54.0
  • @mozilla/readability^0.6.0
  • @sinclair/typebox0.34.48
  • @slack/bolt^4.6.0
  • @slack/web-api^7.14.1
  • ajv^8.18.0
  • chalk^5.6.2
  • chokidar^5.0.0
  • cli-highlight^2.1.11
  • commander^14.0.3
  • croner^10.0.1
  • docx^9.5.1
  • dotenv^17.3.1
  • exceljs^4.4.0
  • express^5.2.1
  • file-type^21.3.0
  • https-proxy-agent^7.0.6
  • jiti^2.6.1
  • json5^2.2.3
  • jszip^3.10.1
  • linkedom^0.18.12
  • …and 18 more.