Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 1,508Niche · −30% score
- Versions published
- 215Mature · −50% score
- First published
- May 2025
- Publisher
- isamu
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts26
audionpx tsx ./src/cli/bin.ts audiobuildtscbuild_testtsc && git checkout -- lib/*ci_testcross-env NODE_ENV=test tsx --test --experimental-test-coverage ./test/*/test_*.tsclinpx tsx ./src/cli/bin.tsdeep_researchnpx tsx ./src/tools/deep_research.tsformatprettier --write '{src,scripts,assets/templates,assets/styles,assets/html/js,draft,ideason,scripts_mag2,proto,test,batch,graphai,output,docs/scripts}/**/*.{ts,js,json,yaml}'generate_action_docsnpx tsx ./automation/generate_actions_docs/generate_action_docs.tshtmlnpx tsx ./src/cli/bin.ts htmlimagesnpx tsx ./src/cli/bin.ts imageslatestyarn upgrade-interactive --latestlinteslint src test assets/html/jsmarkdownnpx tsx ./src/cli/bin.ts markdownmcp_servernpx tsx ./src/mcp/server.tsmovienpx tsx ./src/cli/bin.ts moviepdfnpx tsx ./src/cli/bin.ts pdfpreprocessnpx tsx ./src/cli/bin.ts preprocesspromptnpx tsx ./src/cli/bin.ts tool promptschemanpx tsx ./src/cli/bin.ts tool schemascriptingnpx tsx ./src/cli/bin.ts tool scriptingstory_to_scriptnpx tsx ./src/cli/bin.ts tool story_to_scripttemplatenpx tsx batch/template2tsobject.ts && yarn run formattestrm -f scratchpad/test*.* && npx tsx ./src/audio.ts scripts/test/test.json && npx tsx ./src/images.ts scripts/test/test.json && npx tsx ./src/movie.ts scripts/test/test.jsontranslatenpx tsx ./src/cli/bin.ts translatevoicenpx tsx batch/openai_sample.ts && yarn run movie scripts/samples/openai_voice.jsonwhispernpx tsx ./src/cli/bin.ts tool whisper
Dependencies31
@google-cloud/text-to-speech^6.4.1@google/genai^2.7.0@graphai/anthropic_agent^2.0.12@graphai/browserless_agent^2.0.2@graphai/gemini_agent^2.0.5@graphai/groq_agent^2.0.2@graphai/input_agents^1.0.2@graphai/openai_agent^2.0.9@graphai/stream_agent_filter^2.0.3@graphai/vanilla^2.0.12@graphai/vanilla_node_agents^2.0.4@inquirer/input^5.0.13@inquirer/select^5.1.5@modelcontextprotocol/sdk^1.29.0@modernized/fluent-ffmpeg^1.0.0@mozilla/readability^0.6.0@mulmocast/deck^1.1.0@tavily/core^0.7.3archiver^7.0.1clipboardy^5.3.1dotenv^17.4.2graphai^2.0.17jsdom^29.1.1marked^18.0.5mulmocast-vision^1.0.10ora^9.4.0puppeteer^25.1.0replicate^1.4.0yaml^2.9.0yargs^18.0.0- …and 1 more.