Package evidence
[email protected]
Remote Payload: matched "github.com/user/agent-farm-cli/releases/download"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 388
- Versions published
- 54
- First published
- Apr 2026
- Publisher
- bk201_1393
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "github.com/user/agent-farm-cli/releases/download"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 17 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/dist/application/use-cases/self-update/run-self-update.js | matched "github.com/user/agent-farm-cli/releases/download" | 12 |
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/dist/application/use-cases/self-update/run-self-update.js | matched "github.com/user/agent-farm-cli/releases/download" | 12 |
| low | Install-time lifecycle script | package.json | postinstall="node scripts/postinstall-rebuild-sqlite.mjs" | 5 |
Manifest
Package metadata
Scripts60
agent-farmnode ./dist/interfaces/cli/index.jsagent-farm:devtsx src/interfaces/cli/index.tsbuildnode scripts/clean-dist.mjs && tsc -p tsconfig.json && node scripts/copy-panel-core.mjsbuild:bundlenpm run build && node scripts/bundle-cli.mjsbuild:exenpm run build:bundle && npm run build:seabuild:seanode scripts/build-sea.mjschecktsc -p tsconfig.json --noEmitci:health:localnode scripts/ci-health-local.mjscommitnode scripts/commit.mjsdevtsx src/interfaces/cli/index.tsfarm:control-planenode ./dist/interfaces/cli/index.js control-plane servefarm:cursor-sdk:smokenpm run build && node scripts/cursor-sdk-smoke.mjsfarm:dashboardnode ./dist/interfaces/cli/index.js dashboardfarm:dashboard:opencodenode ./dist/interfaces/cli/index.js dashboard --opencode-feedfarm:dashboard:opencode:devtsx src/interfaces/cli/index.ts dashboard --opencode-feedfarm:dispatchbash scripts/agent-farm-dispatch.shfarm:dispatch:batchbash scripts/agent-farm-dispatch-batch.shfarm:dispatch:batch:nodenode scripts/agent-farm-dispatch-batch.mjsfarm:dispatch:nodenode scripts/agent-farm-dispatch.mjsfarm:dispatch:psnode scripts/agent-farm-dispatch.mjsfarm:doctornode ./dist/interfaces/cli/index.js doctorfarm:doctor:cinode ./dist/interfaces/cli/index.js doctor --ci-exitfarm:initnpm run build && node ./dist/interfaces/cli/index.js project init --target-dir . --force --no-interactive --storage sqlite --environments cursor --executor opencode --workers 4farm:insightsnode ./dist/interfaces/cli/index.js insightsfarm:m1:wavenpm run build && node scripts/agent-farm-dispatch-batch.mjs .agent-farm/waves/m1-cursor-control-plane.jsonfarm:m2:wavenpm run build && node scripts/agent-farm-dispatch-batch.mjs .agent-farm/waves/m2-cursor-sdk-spike.jsonfarm:m3:wavenode scripts/ensure-built.mjs && node scripts/agent-farm-dispatch-batch.mjs examples/waves/m3-product-onboarding.jsonfarm:mcpnode ./dist/interfaces/mcp/server.jsfarm:meta:self-iter:wavenpm run build && node scripts/agent-farm-dispatch-batch.mjs test/fixtures/waves/meta-self-iter-20260510.jsonfarm:onboarding:15minnode scripts/ensure-built.mjs && node scripts/onboarding-15min-check.mjs- …and 30 more.
Dependencies6
@modelcontextprotocol/sdk^1.29.0better-sqlite3^12.9.0commander^14.0.3ink^5.1.0react^18.3.1zod^4.4.3