Package evidence
[email protected]
Remote Payload: matched "github.com/NeoLabs-Systems/NeoAgent/releases/download"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 383
- First published
- Mar 2026
- Publisher
- neo_original_
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "github.com/NeoLabs-Systems/NeoAgent/releases/download"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 12 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/flutter_app/lib/features/onboarding/onboarding_companion_step.dart | matched "github.com/NeoLabs-Systems/NeoAgent/releases/download" | 12 |
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/flutter_app/lib/features/onboarding/onboarding_companion_step.dart | matched "github.com/NeoLabs-Systems/NeoAgent/releases/download" | 12 |
| low | Large Javascript Payload | package/server/public/main.dart.js | 4396955 bytes | 0 |
Manifest
Package metadata
Scripts30
benchmark:memorynode scripts/benchmark-memory.jsbenchmark:memorybench:installnode scripts/install-memorybench-provider.jsbenchmark:tokensnode scripts/benchmark-token-cost.jsdevnode --watch server/index.jsdev:backend./dev/backend.shdev:build./dev/build.shdev:stack./dev/stack.shdev:test./dev/test.shdev:web./dev/web.shdocs:builddocusaurus builddocs:devdocusaurus startdocs:previewdocusaurus serve --dir buildflutter:build:webcd flutter_app && flutter build web --output ../server/public --dart-define=NEOAGENT_BACKEND_URL=${NEOAGENT_BACKEND_URL:-} --dart-define=NEOAGENT_WEB_BUILD_ID=$(node ../scripts/web_build_id.js)flutter:run:webcd flutter_app && flutter run -d chrome --dart-define=NEOAGENT_WEB_BUILD_ID=$(node ../scripts/web_build_id.js)flutter:testcd flutter_app && flutter test ../test/flutter/unit ../test/flutter/widgetflutter:test:unitcd flutter_app && flutter test ../test/flutter/unitflutter:test:widgetcd flutter_app && flutter test ../test/flutter/widgetmanagenode bin/neoagent.jsreleasenpx semantic-releasestartnode server/index.jsstart:guest-agentnode server/guest_agent.jstestnpm run test:backendtest:backendnpm run test:unit && npm run test:integration && npm run test:security && npm run test:contract && npm run test:e2e && npm run test:wstest:contractnode --test --test-reporter=spec test/contract/*.test.jstest:e2enode --test --test-reporter=spec test/e2e/*.test.jstest:integrationnode --test --test-reporter=spec test/integration/*.test.jstest:loadnode test/load/auth_load.jstest:securitynode --test --test-reporter=spec test/security/*.test.jstest:unitnode --test --test-reporter=spec test/backend/unit/*.test.jstest:wsnode --test --test-reporter=spec test/websocket/*.test.js
Dependencies39
@anthropic-ai/sdk^0.39.0@google/generative-ai^0.24.0@modelcontextprotocol/sdk^1.12.1@remotion/cli^4.0.459@slidev/cli^52.15.2@slidev/theme-default^0.25.0baileys^6.7.21bcrypt^6.0.0better-sqlite3^11.8.1better-sqlite3-session-store^0.1.0cors^2.8.5discord.js^14.25.1dotenv^16.4.7express^4.21.2express-rate-limit^7.5.0express-session^1.18.1geoip-lite^1.4.10googleapis^150.0.1helmet^8.0.0multer^1.4.5-lts.1node-cron^3.0.3node-pty^1.0.0nodemailer^8.0.5openai^4.85.4otplib^13.4.0playwright-chromium^1.59.1proper-lockfile^4.1.2puppeteer-core^24.40.0puppeteer-extra^3.3.6puppeteer-extra-plugin-stealth^2.11.2- …and 9 more.