Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@trops/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@trops/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 2789274 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 30 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/index.esm.js | 2789274 bytes | 10 |
| medium | Large Javascript Payload | package/dist/electron/index.js | 2400643 bytes | 10 |
| medium | Large Javascript Payload | package/dist/index.js | 2875350 bytes | 10 |
Manifest
Package metadata
Scripts18
buildnpm run build:renderer && npm run build:electronbuild:electronrollup -c rollup.config.electron.mjs && mkdir -p dist/mcp && cp electron/mcp/mcpServerCatalog.json dist/mcp/ && cp electron/mcp/knownExternalMcpServers.json dist/mcp/ && rm -rf dist/mcp/servers && cp -r electron/mcp/servers dist/mcp/ && node scripts/inject-secrets.jsbuild:rendererrollup -c rollup.config.renderer.mjscheck:untrackednode scripts/check-untracked-sources.jsci./scripts/ci.shci:commit./scripts/ci.sh --commitci:pr./scripts/ci.sh --prci:push./scripts/ci.sh --pushci:release./scripts/ci.sh --releasecleanrm -rf distlint:safelistnode scripts/check-tailwind-safelist.jslint:safelist:updatenode scripts/check-tailwind-safelist.js --update-baselineprdizenode scripts/prdize.jsprepublishOnlynpm run clean && npm run buildprettifyprettier --write "src/**/*.{js,jsx,ts,tsx}" "electron/**/*.js"testjest --watchAll=falsetest:mcpnode --test electron/controller/mcpController.test.js electron/mcp/mcpServerCatalog.test.js electron/mcp/installExternalMcpTool.test.jstest:untracked-pinnode scripts/test-untracked-sources-pin.js
Dependencies28
@anthropic-ai/sdk^0.39.0@fortawesome/fontawesome-svg-core^6.1.1@fortawesome/free-brands-svg-icons^6.1.1@fortawesome/free-solid-svg-icons^6.1.1@fortawesome/react-fontawesome^0.1.18@modelcontextprotocol/sdk^1.26.0JSONStream^1.3.5adm-zip^0.5.16algoliasearch^4.13.0clsx^2.1.1croner^10.0.1css^3.0.0csv-parser^3.0.0deep-equal^2.2.0electron-store^8.0.1esbuild^0.25.12live-plugin-manager^0.17.1marked^17.0.5minimist^1.2.8node-forge^1.3.1node-vibrant^4.0.4objects-to-csv^1.3.6openai^4.30.0quickjs-emscripten^0.32.0ws^8.19.0xml2js^0.6.2xtreamer^1.1.2zod^3.23.8