Package evidence
@zenalexa/[email protected]
Known Indicator Filename: package/dist/browser/stealth.js
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 38
- First published
- Apr 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@zenalexa/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@zenalexa/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Known Indicator Filename: package/dist/browser/stealth.js
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 27 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Known Indicator Filename | package/dist/browser/stealth.js | package/dist/browser/stealth.js | 45 |
| high | Known Indicator Filename | package/src/adapters/amazon/discussion.yaml | package/src/adapters/amazon/discussion.yaml | 45 |
Manifest
Package metadata
Scripts59
adapter:bootstraptsx scripts/bootstrap-adapter-tests.tsadapter:healthtsx scripts/adapter-health-probe.tsbenchtsx bench/report.tsbench:agenttsx bench/agent/sdk-runner.tsbench:gatenode scripts/bench/check-ship-gate.jsbench:quicktsx bench/agent/report.tsbench:self-discoverytsx bench/self-discovery.tsbench:surface-coveragetsx bench/surface-coverage.tsboundary:checktsx scripts/boundary-guard.tsbuildnpm run clean && tsc && tsx scripts/build-manifest.js && tsx scripts/count-stats.ts && tsx scripts/build-readme.ts && tsx scripts/build-agents.ts && prettier --write AGENTS.mdbuild:agentstsx scripts/build-agents.tsbuild:manifesttsx scripts/build-manifest.jschangesetchangesetchangeset:statuschangeset status --since=origin/mainchangeset:versionchangeset versioncheck:exportstsx scripts/check-exports-count.tscleannode -e "require('node:fs').rmSync('dist',{recursive:true,force:true})"compute:smoketsx scripts/compute-live-smoke.tsconformancetsx scripts/conformance-report.tscoverage:adapter-testtsx scripts/check-adapter-test-coverage.ts --threshold 50coverage:compute-snapshotvitest run --project unit tests/unit/refs.test.ts tests/unit/snapshot-encoder.test.ts --coverage --coverage.enabled=true --coverage.provider=v8 --coverage.include=src/transport/refs.ts --coverage.include=src/transport/snapshot-encoder.ts --coverage.reporter=text --coverage.thresholds.lines=100 --coverage.thresholds.functions=100 --coverage.thresholds.branches=100 --coverage.thresholds.statements=100devtsx src/main.tsdocs:buildnpm run docs:prepare && node -e "require('node:fs').rmSync('docs/.vitepress/dist',{recursive:true,force:true})" && vitepress build docs && npm run docs:check-publicdocs:check-publictsx scripts/check-public-docs.tsdocs:devnpm run docs:prepare && vitepress dev docsdocs:preparetsx scripts/generate-catalog.ts && tsx scripts/generate-docs-agent-assets.tsdocs:previewvitepress preview docsdoctortsx src/doctor.tse2e:realnpm run build && tsx scripts/e2e-real-matrix.tsformatprettier --write .- …and 29 more.
Dependencies12
ajv^8.20.0ajv-formats^3.0.1chalk^5.6.2cli-table3^0.6.5commander^14.0.3fast-xml-parser^5.8.0js-yaml^4.1.1jsonpath-plus^10.4.0turndown^7.2.4undici^8.3.0ws^8.21.0zod^4.4.3