PkgRadar

Package evidence

@treeseed/[email protected]

Remote Dependency Spec: dependencies.@treeseed/sdk="github:treeseed-ai/sdk#0.11.0"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
40
First published
May 2026
Publisher
adrianwebb

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@treeseed/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@treeseed/[email protected]"],"fail_on":"review"}'
Publisheradrianwebb
Artifact bytes242,033
Previous version0.10.21
Published2026-06-12T08:43:37.966Z
SHA-256b2eecdc3ab0111fe831f9591695a0173375ab084d1b4c65cc0a7602951267e80

Why flagged

What the scanner saw

Remote Dependency Spec: dependencies.@treeseed/sdk="github:treeseed-ai/sdk#0.11.0"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
24Score
0.11.0Version
Status history (1 event)
  1. newavailable · risk review · score 24 · status changed

Evidence

Static findings

1 static · 1 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Dependency Specpackage.jsondependencies.@treeseed/sdk="github:treeseed-ai/sdk#0.11.0"12
mediumDependency Changed To Remote Vs Previouspackage.jsondependencies.@treeseed/sdk changed to remote spec in 0.11.0 vs 0.10.21: "github:treeseed-ai/sdk#0.11.0"12

Manifest

Package metadata

Scripts41
  • buildnpm run build:dist
  • build:distnode ./scripts/run-ts.mjs ./scripts/build-dist.ts
  • capacity-provider:buildnode ./scripts/run-ts.mjs ./scripts/build-capacity-provider-container.ts
  • capacity-provider:test-localnode ./dist/scripts/test-capacity-provider-container.js
  • dev:managernode ./scripts/run-ts.mjs ./src/services/manager.ts
  • dev:remote-runnernode ./scripts/run-ts.mjs ./src/services/remote-runner.ts
  • dev:workday-reportnode ./scripts/run-ts.mjs ./src/services/workday-report.ts
  • dev:workday-startnode ./scripts/run-ts.mjs ./src/services/workday-start.ts
  • dev:workernode ./scripts/run-ts.mjs ./src/services/worker.ts
  • lintnpm run build:dist
  • prepacknpm run build:dist
  • preparenode ./scripts/prepare.mjs
  • release:check-tagnode ./scripts/run-ts.mjs ./scripts/assert-release-tag-version.ts
  • release:publishnode ./scripts/run-ts.mjs ./scripts/publish-package.ts
  • release:setupnpm run setup:ci
  • release:verifynode ./scripts/run-ts.mjs ./scripts/release-verify.ts
  • runtime:readinessnode ./scripts/run-ts.mjs ./scripts/runtime-readiness.ts
  • setupnpm install
  • setup:cinpm ci
  • start:local-manager-cloudflarebash ./scripts/run-local-manager-cloudflare.sh
  • start:managernode ./dist/services/manager.js
  • start:runtime-readinessnode ./dist/scripts/runtime-readiness.js
  • start:workday-reportnode ./dist/services/workday-report.js
  • start:workday-startnode ./dist/services/workday-start.js
  • start:workernode ./dist/services/worker.js
  • testnpm run test:unit && npm run test:smoke
  • test:agent-contractsvitest run --config ./vitest.config.ts test/agents/agent-contracts.test.ts test/agents/agent-test-catalog.test.ts
  • test:agent-handlersvitest run --config ./vitest.config.ts test/agents/handler-fixtures.test.ts test/agents/knowledge-handlers.test.ts
  • test:agent-message-chainsvitest run --config ./vitest.config.ts test/agents/message-chain.test.ts test/services/research-knowledge-workday.test.ts
  • test:capacity-provider-runtimevitest run --config ./vitest.config.ts test/provider/capacity-provider-runtime.test.ts
  • …and 11 more.
Dependencies6
  • @openai/codex-sdk^0.130.0
  • @treeseed/sdkgithub:treeseed-ai/sdk#0.11.0
  • esbuild0.28.0
  • hono^4.8.2
  • typescript^5.9.3
  • yaml^2.8.1