PkgRadar

Package evidence

@zenith-cli/[email protected]

Install Lifecycle Remote Or Exec: postinstall="node scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
2
First published
May 2026
Publisher
naresh007

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@zenith-cli/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@zenith-cli/[email protected]"],"fail_on":"high"}'
Publishernaresh007
Artifact bytes2,622,122
Previous versionnone
Published2026-05-25T11:15:53.597Z
SHA-2564848e9212e19cc6c8e9b8a68a9ba864959020a2c093b69e257ef5f9a6674db73

Why flagged

What the scanner saw

Install Lifecycle Remote Or Exec: postinstall="node scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

scan error

status
Last checked
noneRisk
Score
0.1.0-beta.1Version

Latest scanner note: HTTP status client error (404 Not Found) for url (https://registry.npmjs.org/%40zenith-cli%2Fzenith)

Status history (2 events)
  1. availablescan_error · risk none · score · HTTP status client error (404 Not Found) for url (https://registry.npmjs.org/%40zenith-cli%2Fzenith)
  2. newavailable · risk high · score 117 · status changed

Evidence

Static findings

34 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highInstall Lifecycle Remote Or Execpackage.jsonpostinstall="node scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js"30
mediumRemote Payloadpackage/scripts/check-sqlite.jsmatched "github.com/WiseLibs/better-sqlite3/releases/download"12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/messaging/rabbitmq/scripts/check-cluster.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/networking/traefik/scripts/check-dashboard.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/grafana/scripts/check-dashboards.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/elk-stack/scripts/check-ilm.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/loki/scripts/check-streams.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/csharp/aspnet-core/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/csharp/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/elixir/phoenix/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/golang/echo/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/golang/gin/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/micronaut/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/quarkus/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/springboot/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/fastify/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/koa/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/nestjs/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/kotlin/ktor/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/php/laravel/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/php/symfony/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/ruby/rails/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/rust/actix-web/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/rust/axum/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/grafana/scripts/test-alert-channel.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/prometheus/scripts/test-alert.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/security/web-security/scripts/test-hsts.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/loki/scripts/test-query.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/security/web-security/scripts/validate-headers.shmatched "curl "12
Show all 34 findings (low-signal and informational)
SeverityKindPathDetailPoints
highInstall Lifecycle Remote Or Execpackage.jsonpostinstall="node scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js"30
mediumRemote Payloadpackage/scripts/check-sqlite.jsmatched "github.com/WiseLibs/better-sqlite3/releases/download"12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/messaging/rabbitmq/scripts/check-cluster.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/networking/traefik/scripts/check-dashboard.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/grafana/scripts/check-dashboards.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/elk-stack/scripts/check-ilm.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/loki/scripts/check-streams.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/csharp/aspnet-core/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/csharp/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/elixir/phoenix/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/golang/echo/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/golang/gin/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/micronaut/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/quarkus/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/java/springboot/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/fastify/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/koa/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/javascript/nestjs/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/kotlin/ktor/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/php/laravel/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/php/symfony/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/ruby/rails/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/rust/actix-web/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/backend/rust/axum/scripts/health-check.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/grafana/scripts/test-alert-channel.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/prometheus/scripts/test-alert.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/security/web-security/scripts/test-hsts.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/devops/observability/loki/scripts/test-query.shmatched "curl "12
mediumRemote Payloadpackage/core/assets/default-skills/domain/technical/security/web-security/scripts/validate-headers.shmatched "curl "12
lowCredential file accesspackage/core/dist/security/checks/PathBoundaryCheck.jsmatched ".ssh"5
lowCredential file accesspackage/core/dist/security/checks/SecretRedactionCheck.jsmatched "aws_access_key"5
lowCredential file accesspackage/core/assets/default-skills/domain/technical/devops/networking/istio/scripts/validate-mesh.pymatched "kubeconfig"5
lowCredential file accesspackage/core/assets/default-skills/domain/technical/devops/ci-cd/github-actions/scripts/validate-workflow.pymatched "GITHUB_TOKEN"5
lowInstall-time lifecycle scriptpackage.jsonpostinstall="node scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js"5

Manifest

Package metadata

Scripts7
  • buildpnpm -r run build
  • devpnpm -r run dev
  • pack:betapnpm -r run build && npm pack
  • postinstallnode scripts/check-sqlite.js && node scripts/check-kuzu.js && node scripts/link-workspace.js
  • publish:betapnpm -r run build && npm publish --tag beta
  • testpnpm -r run test
  • test:watchpnpm -r run test:watch
Dependencies18
  • @anthropic-ai/sdk^0.30.1
  • @clack/prompts^1.4.0
  • @fastify/cors^8.5.0
  • @fastify/rate-limit^7.6.0
  • @modelcontextprotocol/sdk^1.0.0
  • chalk^5.3.0
  • chokidar^3.6.0
  • cli-progress^3.12.0
  • commander^12.1.0
  • fastify^4.27.0
  • js-tiktoken^1.0.12
  • js-yaml^4.1.0
  • openai^4.67.3
  • ora^8.0.1
  • shell-quote^1.8.1
  • sqlite-vec^0.1.7-alpha.2
  • ws^8.18.0
  • zod^3.23.8
Optional dependencies14
  • @xenova/transformers^2.17.2
  • better-sqlite3^12.8.0
  • kuzu0.11.3
  • node-notifier^10.0.1
  • tree-sitter0.22.1
  • tree-sitter-c-sharp~0.21.0
  • tree-sitter-cpp~0.21.0
  • tree-sitter-go~0.21.0
  • tree-sitter-java~0.21.0
  • tree-sitter-javascript~0.21.0
  • tree-sitter-python~0.21.0
  • tree-sitter-ruby~0.21.0
  • tree-sitter-rust~0.21.0
  • tree-sitter-typescript~0.21.0