Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 22
- First published
- Feb 2026
- Publisher
- ah-wq
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts41
catalog:generatenode scripts/generate-catalog-docs.jscatalog:skill-indexnode scripts/generate-skill-index.jsdoctor:omcodexnode bin/omcodex.js doctoreval:skillsnode scripts/eval-skills.jsgovernance:harness./scripts/check-harness-governance.shgovernance:skills./scripts/check-skill-governance.shgovernance:skills:llmnode scripts/check-skill-llm-governance.js --mode=autogovernance:skills:overlapnode scripts/report-skill-overlap-governance.jsgovernance:skills:overlap:multinode scripts/report-multi-upstream-overlap.jsgovernance:skills:patches./scripts/generate-upstream-overlap-patches.shgovernance:skills:sources./scripts/test-skill-governance-sources.shharness:graphnode bin/omcodex.js harness graphharness:intentsnode bin/omcodex.js harness intentsharness:lintnode bin/omcodex.js harness lintharness:migratenode scripts/add-harness-metadata.jsinstall:codex./scripts/install-codex.shmcp:codex./scripts/generate-codex-mcp-config.shpack:dry-runnpm pack --dry-runprepublishOnlynpm run source:skills:sync -- --skip-fetch && npm testsetup:omcodexnode bin/omcodex.js setupskill:conflictsnode bin/omcodex.js skill conflictsskill:listnode bin/omcodex.js skill listskill:migratenode scripts/migrate-skill-metadata.jssource:listnode bin/omcodex.js source listsource:skills:sync./scripts/sync-upstream-skills.sh --source allsource:skills:sync:ecc./scripts/sync-ecc.shsource:skills:sync:omc./scripts/sync-upstream-skills.sh --source oh-my-codexsource:skills:sync:sp./scripts/sync-upstream-skills.sh --source superpowerssource:statusnode bin/omcodex.js source statussource:syncnode bin/omcodex.js source sync- …and 11 more.
Dependencies1
@modelcontextprotocol/sdk^1.0.0