PkgRadar

Package evidence

@tmecontinue/[email protected]

Credential file access: matched ".Aws"

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@tmecontinue/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@tmecontinue/[email protected]"],"fail_on":"review"}'
Publishertmecontinue
Artifact bytes14,648,157
Previous version2.2.14
Published2026-05-22T11:52:15.416Z
SHA-256f9b27412ab8f52388d2004560af0cf02ddda5a56213aaddec8347af0615b8685

Why flagged

What the scanner saw

Credential file access: matched ".Aws"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
272Score
2.2.15-beta.1Version
Status history (1 event)
  1. newavailable · risk review · score 272 · status changed

Evidence

Static findings

157 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspackage/dist/chunk-h0rfe6tr.jsmatched ".Aws"30
mediumRemote Payloadpackage/dist/chunk-c8y9dsaf.jsmatched "curl "12
mediumObfuscation Densitypackage/dist/chunk-fcr5cx6m.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-qee79kwt.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-rzzqmzzb.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-s8tym74c.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-tp6894d8.jshigh encoded/escaped-token density12
mediumCredential file accesspackage/dist/chunk-5znrt89f.jsmatched ".AWS"10
mediumLarge Javascript Payloadpackage/dist/chunk-79h21yza.js4527537 bytes10
mediumCredential file accesspackage/dist/chunk-ck9er9an.jsmatched ".SSH"10
mediumCredential file accesspackage/dist/chunk-dz0c6y7y.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-j53664tc.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-m0z0gqf3.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-t2e63g80.jsmatched "AWS_ACCESS_KEY"10
mediumCredential file accesspackage/dist/chunk-t57gzb56.jsmatched ".aws"10
mediumCredential file accesspackage/dist/chunk-x2ta3jd7.jsmatched "AWS_ACCESS_KEY"10
Show all 157 findings (low-signal and informational)

Showing 60 of 157 findings.

SeverityKindPathDetailPoints
highCredential file accesspackage/dist/chunk-h0rfe6tr.jsmatched ".Aws"30
mediumRemote Payloadpackage/dist/chunk-c8y9dsaf.jsmatched "curl "12
mediumObfuscation Densitypackage/dist/chunk-fcr5cx6m.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-qee79kwt.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-rzzqmzzb.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-s8tym74c.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-tp6894d8.jshigh encoded/escaped-token density12
mediumCredential file accesspackage/dist/chunk-5znrt89f.jsmatched ".AWS"10
mediumLarge Javascript Payloadpackage/dist/chunk-79h21yza.js4527537 bytes10
mediumCredential file accesspackage/dist/chunk-ck9er9an.jsmatched ".SSH"10
mediumCredential file accesspackage/dist/chunk-dz0c6y7y.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-j53664tc.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-m0z0gqf3.jsmatched ".AWS"10
mediumCredential file accesspackage/dist/chunk-t2e63g80.jsmatched "AWS_ACCESS_KEY"10
mediumCredential file accesspackage/dist/chunk-t57gzb56.jsmatched ".aws"10
mediumCredential file accesspackage/dist/chunk-x2ta3jd7.jsmatched "AWS_ACCESS_KEY"10
lowCredential file accesspackage/dist/chunk-1s3678qc.jsmatched ".azure"5
lowCredential file accesspackage/dist/chunk-28m3z941.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-5zjbad4x.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-6dw30z4j.jsmatched ".AWS"5
lowCredential file accesspackage/dist/chunk-7rb7486z.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-8p5s2yhn.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-9r4krbga.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-dw989mwr.jsmatched ".Aws"5
lowCredential file accesspackage/dist/chunk-h2n147vd.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-k0mv7n12.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-kwvb5bxg.jsmatched "AWS_SECRET_ACCESS_KEY"5
lowCredential file accesspackage/dist/chunk-m24fv50v.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-n2g9z7vg.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-p023dczz.jsmatched ".Azure"5
lowCredential file accesspackage/dist/chunk-r3j9jeen.jsmatched ".aws"5
lowCredential file accesspackage/dist/chunk-t4bvhyf7.jsmatched ".Aws"5
lowCredential file accesspackage/dist/chunk-vfzeb0jn.jsmatched ".npmrc"5
lowCredential file accesspackage/dist/chunk-vh24bqzg.jsmatched ".AWS"5
lowCredential file accesspackage/dist/chunk-wtk9f32a.jsmatched ".aws"5
lowObfuscationpackage/dist/chunk-0048dt45.jsmatched "\\u2026"3
lowObfuscationpackage/dist/chunk-0teavzhs.jsmatched "\\u03C9"3
lowObfuscationpackage/dist/chunk-0tj3r6vh.jsmatched "\\u2026"3
lowObfuscationpackage/dist/chunk-0zabjen7.jsmatched "Buffer.from($,\"base64"3
lowObfuscationpackage/dist/chunk-0zz1prrf.jsmatched "\\x1B"3
lowObfuscationpackage/dist/chunk-107qd9jy.jsmatched "\\uFEFF"3
lowObfuscationpackage/dist/chunk-1bhx15z3.jsmatched "\\x00"3
lowObfuscationpackage/dist/chunk-1gkk3mxy.jsmatched "\\xB7"3
lowObfuscationpackage/dist/chunk-1kfhfypy.jsmatched "\\x21"3
lowObfuscationpackage/dist/chunk-257nyzv3.jsmatched "\\u250C"3
lowObfuscationpackage/dist/chunk-28m3z941.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-2atrt203.jsmatched "\\uD83D"3
lowObfuscationpackage/dist/chunk-35bbjzc2.jsmatched "\\u2022"3
lowObfuscationpackage/dist/chunk-3a2m6sjg.jsmatched "\\u2026"3
lowObfuscationpackage/dist/chunk-3s6pjeac.jsmatched "\\u2192"3
lowObfuscationpackage/dist/chunk-4655ad65.jsmatched "\\xB7"3
lowObfuscationpackage/dist/chunk-4kvrgaap.jsmatched "\\u2192"3
lowObfuscationpackage/dist/chunk-4njp9dgx.jsmatched "\\u2014"3
lowObfuscationpackage/dist/chunk-4r6sagxv.jsmatched "\\u2022"3
lowObfuscationpackage/dist/chunk-4t5yke6b.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/chunk-5mf405m7.jsmatched "\\xB7"3
lowObfuscationpackage/dist/chunk-5mk66np1.jsmatched "\\u2026"3
lowObfuscationpackage/dist/chunk-62a07e48.jsmatched "\\xB7"3
lowObfuscationpackage/dist/chunk-62qz9cse.jsmatched "\\u2514"3
lowObfuscationpackage/dist/chunk-6515vw1h.jsmatched "\\u2014"3

Manifest

Package metadata

Scripts14
  • buildbun run download:ripgrep && bun run build.ts
  • check:unusedknip-bun
  • devbun run src/entrypoints/cli.tsx --debug
  • docs:devnpx mintlify dev
  • download:ripgrepbun run scripts/download-ripgrep.ts
  • formatbiome format --write src/
  • healthbun run scripts/health-check.ts
  • lintbiome lint src/
  • lint:fixbiome lint --fix src/
  • preparegit config core.hooksPath .githooks
  • prepublishOnlybun run build
  • publish:betanpm publish --tag beta
  • publish:latestnpm publish
  • testbun test
Dependencies2
  • claude-adapter^2.1.0
  • undici^7.24.6