Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@tmecontinue/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@tmecontinue/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Credential file access: matched ".Aws"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 272 · status changed
Evidence
Static findings
157 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential file access | package/dist/chunk-dnh94kvq.js | matched ".Aws" | 30 |
| medium | Obfuscation Density | package/dist/chunk-312nh9q5.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-j8762rfe.js | high encoded/escaped-token density | 12 |
| medium | Remote Payload | package/dist/chunk-jtjvx8nz.js | matched "curl " | 12 |
| medium | Obfuscation Density | package/dist/chunk-kdpnvg0y.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-mf4551vg.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-r05jehc4.js | high encoded/escaped-token density | 12 |
| medium | Large Javascript Payload | package/dist/chunk-7yfkzx7n.js | 4528749 bytes | 10 |
| medium | Credential file access | package/dist/chunk-gvs6c7rj.js | matched "AWS_ACCESS_KEY" | 10 |
| medium | Credential file access | package/dist/chunk-qjzycreh.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-s6crfgv7.js | matched ".SSH" | 10 |
| medium | Credential file access | package/dist/chunk-snhf4je0.js | matched ".aws" | 10 |
| medium | Credential file access | package/dist/chunk-tmqqxs2z.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-waxcze3a.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-x715kafv.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-yw530z82.js | matched "AWS_ACCESS_KEY" | 10 |
Show all 157 findings (low-signal and informational)
Showing 60 of 157 findings.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential file access | package/dist/chunk-dnh94kvq.js | matched ".Aws" | 30 |
| medium | Obfuscation Density | package/dist/chunk-312nh9q5.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-j8762rfe.js | high encoded/escaped-token density | 12 |
| medium | Remote Payload | package/dist/chunk-jtjvx8nz.js | matched "curl " | 12 |
| medium | Obfuscation Density | package/dist/chunk-kdpnvg0y.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-mf4551vg.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/dist/chunk-r05jehc4.js | high encoded/escaped-token density | 12 |
| medium | Large Javascript Payload | package/dist/chunk-7yfkzx7n.js | 4528749 bytes | 10 |
| medium | Credential file access | package/dist/chunk-gvs6c7rj.js | matched "AWS_ACCESS_KEY" | 10 |
| medium | Credential file access | package/dist/chunk-qjzycreh.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-s6crfgv7.js | matched ".SSH" | 10 |
| medium | Credential file access | package/dist/chunk-snhf4je0.js | matched ".aws" | 10 |
| medium | Credential file access | package/dist/chunk-tmqqxs2z.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-waxcze3a.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-x715kafv.js | matched ".AWS" | 10 |
| medium | Credential file access | package/dist/chunk-yw530z82.js | matched "AWS_ACCESS_KEY" | 10 |
| low | Credential file access | package/dist/chunk-1cawq38b.js | matched ".Azure" | 5 |
| low | Credential file access | package/dist/chunk-1n6dkk2e.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-4zbc776h.js | matched ".Aws" | 5 |
| low | Credential file access | package/dist/chunk-5h96y5bp.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-5m6kdsv8.js | matched ".azure" | 5 |
| low | Credential file access | package/dist/chunk-6y6b4srr.js | matched ".AWS" | 5 |
| low | Credential file access | package/dist/chunk-83w7adw7.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-acgvzyet.js | matched ".Aws" | 5 |
| low | Credential file access | package/dist/chunk-cv99dn1g.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-d4pr4vsa.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-fmz482ja.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-k60gvdzm.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-pn3ptttf.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-t41ggmmc.js | matched ".npmrc" | 5 |
| low | Credential file access | package/dist/chunk-tttq1t2p.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-tyme29wj.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-wfrhrg5y.js | matched ".aws" | 5 |
| low | Credential file access | package/dist/chunk-xf05kb1q.js | matched "AWS_SECRET_ACCESS_KEY" | 5 |
| low | Credential file access | package/dist/chunk-xqn0hg22.js | matched ".AWS" | 5 |
| low | Obfuscation | package/dist/chunk-0a1h1fhy.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-0egd3vrw.js | matched "\\u2022" | 3 |
| low | Obfuscation | package/dist/chunk-0v4rnrhp.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-1cawq38b.js | matched "Buffer.from(Z,w.EncodingTypes.BASE64" | 3 |
| low | Obfuscation | package/dist/chunk-1e5dyh2v.js | matched "\\u26A0" | 3 |
| low | Obfuscation | package/dist/chunk-1hk091vg.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-1ma8kaqs.js | matched "\\xB7" | 3 |
| low | Obfuscation | package/dist/chunk-1na6f205.js | matched "\\u25C7" | 3 |
| low | Obfuscation | package/dist/chunk-25536rxj.js | matched "\\uFEFF" | 3 |
| low | Obfuscation | package/dist/chunk-29qmfmjv.js | matched "\\u2713" | 3 |
| low | Obfuscation | package/dist/chunk-2tg7jq57.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-30a4krbs.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-312nh9q5.js | matched "\\xC1" | 3 |
| low | Obfuscation | package/dist/chunk-35ex5w1n.js | matched "\\x1B" | 3 |
| low | Obfuscation | package/dist/chunk-3sbbysjp.js | matched "\\u2014" | 3 |
| low | Obfuscation | package/dist/chunk-3w3ewbv1.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/dist/chunk-446he7t2.js | matched "\\u2014" | 3 |
| low | Obfuscation | package/dist/chunk-4kcgt6xw.js | matched "\\u03C9" | 3 |
| low | Obfuscation | package/dist/chunk-4zbc776h.js | matched "\\x1B" | 3 |
| low | Obfuscation | package/dist/chunk-53vv7186.js | matched "\\xB7" | 3 |
| low | Obfuscation | package/dist/chunk-5wkhd068.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-6fa400a7.js | matched "\\x1B" | 3 |
| low | Obfuscation | package/dist/chunk-6jfb94fm.js | matched "\\u2026" | 3 |
| low | Obfuscation | package/dist/chunk-6nr6wc22.js | matched "\\u2019" | 3 |
| low | Obfuscation | package/dist/chunk-6yfb09zj.js | matched "\\xB7" | 3 |
Manifest
Package metadata
Scripts14
buildbun run download:ripgrep && bun run build.tscheck:unusedknip-bundevbun run src/entrypoints/cli.tsx --debugdocs:devnpx mintlify devdownload:ripgrepbun run scripts/download-ripgrep.tsformatbiome format --write src/healthbun run scripts/health-check.tslintbiome lint src/lint:fixbiome lint --fix src/preparegit config core.hooksPath .githooksprepublishOnlybun run buildpublish:betanpm publish --tag betapublish:latestnpm publishtestbun test
Dependencies2
claude-adapter^2.1.0undici^7.24.6