PkgRadar

Package evidence

[email protected]

Remote Dependency Spec: optionalDependencies.@kuzushi/tob-skills="github:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
12
Versions published
22
First published
Feb 2026
Publisher
snejad123

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publishersnejad123
Artifact bytes38,831,209
Previous version0.20.0
Published2026-06-12T15:55:32.721Z
SHA-25650a6e54b805e02818c64af67ae706c4b23a0030674e2b6e7c654ae18fe51fca6

Why flagged

What the scanner saw

New Lifecycle Script Vs Previous: postinstall added in 0.24.0-alpha.4 vs 0.20.0: "node scripts/check-native-bindings.mjs"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
245Score
0.24.0-alpha.4Version
Status history (1 event)
  1. newavailable · risk high · score 245 · status changed

Evidence

Static findings

5 static · 5 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highNew Lifecycle Script Vs Previouspackage.jsonpostinstall added in 0.24.0-alpha.4 vs 0.20.0: "node scripts/check-native-bindings.mjs"40
highRemote Dependency Specpackage.jsonoptionalDependencies.@kuzushi/tob-skills="github:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2"35
highRemote Dependency Specpackage.jsonoptionalDependencies.@kuzushi/vuln-scout="github:allsmog/vuln-scout#79df9e804c6a87f0af3c779c55d2fcdb4675f49d"35
highRemote Dependency Specpackage.jsonoptionalDependencies.promptarmor-plugin="github:allsmog/promptarmor-plugin#690d60a5b4d2136206ef7dedd516d3fcfddd4db9"35
highRemote Dependency Specpackage.jsonoptionalDependencies.shinsa-plugin="github:allsmog/shinsa-plugin#74b3737d225970d849f5f6f57095cfe65ee7ccdf"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.@kuzushi/tob-skills added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.@kuzushi/vuln-scout added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/vuln-scout#79df9e804c6a87f0af3c779c55d2fcdb4675f49d"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.promptarmor-plugin added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/promptarmor-plugin#690d60a5b4d2136206ef7dedd516d3fcfddd4db9"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.shinsa-plugin added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/shinsa-plugin#74b3737d225970d849f5f6f57095cfe65ee7ccdf"35
Show all 10 findings (low-signal and informational)
SeverityKindPathDetailPoints
highNew Lifecycle Script Vs Previouspackage.jsonpostinstall added in 0.24.0-alpha.4 vs 0.20.0: "node scripts/check-native-bindings.mjs"40
highRemote Dependency Specpackage.jsonoptionalDependencies.@kuzushi/tob-skills="github:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2"35
highRemote Dependency Specpackage.jsonoptionalDependencies.@kuzushi/vuln-scout="github:allsmog/vuln-scout#79df9e804c6a87f0af3c779c55d2fcdb4675f49d"35
highRemote Dependency Specpackage.jsonoptionalDependencies.promptarmor-plugin="github:allsmog/promptarmor-plugin#690d60a5b4d2136206ef7dedd516d3fcfddd4db9"35
highRemote Dependency Specpackage.jsonoptionalDependencies.shinsa-plugin="github:allsmog/shinsa-plugin#74b3737d225970d849f5f6f57095cfe65ee7ccdf"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.@kuzushi/tob-skills added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.@kuzushi/vuln-scout added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/vuln-scout#79df9e804c6a87f0af3c779c55d2fcdb4675f49d"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.promptarmor-plugin added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/promptarmor-plugin#690d60a5b4d2136206ef7dedd516d3fcfddd4db9"35
highNew Remote Dependency Vs Previouspackage.jsonoptionalDependencies.shinsa-plugin added in 0.24.0-alpha.4 vs 0.20.0: "github:allsmog/shinsa-plugin#74b3737d225970d849f5f6f57095cfe65ee7ccdf"35
lowInstall-time lifecycle scriptpackage.jsonpostinstall="node scripts/check-native-bindings.mjs"5

Manifest

Package metadata

Scripts51
  • benchmarktsx benchmarks/harness.ts
  • benchmark:difftsx benchmarks/sarif-diff.ts
  • benchmark:freezetsx benchmarks/freeze-baseline.ts
  • benchmark:regressiontsx benchmarks/regression-check.ts
  • benchmark:scoreboardtsx benchmarks/scoreboard.ts
  • buildtsc
  • build:cleanpnpm clean:dist && tsc
  • build:nativecargo build -p kuzushi-cli --release && node scripts/stage-native-binary.mjs
  • build:rustcargo build --workspace
  • checkbiome check .
  • check:circularmadge --ts-config tsconfig.json --extensions ts --circular src/
  • check:docsnode scripts/check-port-contract.mjs && node scripts/check-public-identity.mjs && node scripts/check-doc-command-drift.mjs && node scripts/check-retired-ts-runtime.mjs
  • check:retired-ts-runtimenode scripts/check-retired-ts-runtime.mjs
  • check:typesnode scripts/typecheck-all.mjs
  • clean:distnode -e "require('node:fs').rmSync('dist',{recursive:true,force:true})"
  • codegentsx scripts/codegen/index.ts
  • codegen:checktsx scripts/codegen/check.ts
  • complexitynode scripts/cyclomatic.mjs src --top 30 --min 20
  • complexity:logicnode scripts/cyclomatic.mjs src --top 30 --min 20 --logic-only
  • devcargo run -p kuzushi-cli
  • dev:rustcargo run -p kuzushi-cli
  • doctorbash scripts/doctor.sh
  • eval:kuzushi-whitebox-staticnode --import tsx evals/kuzushi-whitebox-static/run.ts
  • export:sourcebash scripts/export-clean-source.sh
  • fixbiome check --write .
  • fix:unsafebiome check --write --unsafe .
  • formatbiome format .
  • lintbiome lint .
  • perftsx perf/harness.ts
  • postinstallnode scripts/check-native-bindings.mjs
  • …and 21 more.
Dependencies16
  • @anthropic-ai/sdk^0.81.0
  • @kuzushi/augur^0.1.0
  • @langchain/anthropic^1.0.0
  • @langchain/core^1.0.0
  • @langchain/langgraph^1.0.0
  • @langchain/mcp-adapters^1.0.0
  • @langchain/openai^1.0.0
  • better-sqlite3^12.8.0
  • chalk^5.4.1
  • commander^13.1.0
  • langchain^1.0.0
  • tinyglobby^0.2.15
  • typescript^5.7.3
  • undici^7.22.0
  • yaml^2.7.0
  • zod^4.3.6
Optional dependencies4
  • @kuzushi/tob-skillsgithub:allsmog/tob-security-skills#98dda39a53eb74b90d60f305c8523e47552a9fb2
  • @kuzushi/vuln-scoutgithub:allsmog/vuln-scout#79df9e804c6a87f0af3c779c55d2fcdb4675f49d
  • promptarmor-plugingithub:allsmog/promptarmor-plugin#690d60a5b4d2136206ef7dedd516d3fcfddd4db9
  • shinsa-plugingithub:allsmog/shinsa-plugin#74b3737d225970d849f5f6f57095cfe65ee7ccdf