Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 603
- Versions published
- 31
- First published
- Mar 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Credential file access: matched "GITHUB_TOKEN"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 6 · status changed
Evidence
Static findings
4 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 4 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Credential file access | package/dist/cms-migrations.js | matched "GITHUB_TOKEN" | 5 |
| low | Credential file access | package/dist/model-providers.js | matched "GITHUB_TOKEN" | 5 |
| low | Credential file access | package/dist/session-manager.js | matched "GITHUB_TOKEN" | 5 |
| low | Credential file access | package/dist/sweeper-tools.js | matched ".azure" | 5 |
Manifest
Package metadata
Scripts30
buildtsccleanrm -rf distdevtsc --watchlinttsc --noEmittestnode --env-file=../../.env test/sdk.test.jstest:localnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs runtest:local:agent-tunernode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/agent-tuner.test.jstest:local:cache-observabilitynode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/cache-observability.test.jstest:local:chaosnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/chaos.test.jstest:local:cmsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/cms-*.test.jstest:local:commandsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/commands-*.test.jstest:local:contractsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/contracts.test.jstest:local:cross-sessionnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/cross-session-messaging.test.jstest:local:dehydrate-no-fallbacknode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/dehydrate-no-fallback.test.jstest:local:durabilitynode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/durability.test.js test/local/wait-*.test.jstest:local:facts-statsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/facts-stats.test.jstest:local:inspect-toolsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/inspect-tools.test.jstest:local:knowledge-pipelinenode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/knowledge-pipeline.test.js test/local/facts.test.jstest:local:kv-transportnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/kv-transport.test.jstest:local:managementnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/management.test.jstest:local:multi-workernode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/multi-worker.test.jstest:local:reliabilitynode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/reliability-*.test.jstest:local:sdk-disk-formatnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/sdk-disk-format.test.jstest:local:session-policynode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/session-policy-*.test.jstest:local:skill-usagenode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/skill-usage.test.jstest:local:smokenode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/smoke-*.test.jstest:local:sub-agentsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/sub-agents/*.test.jstest:local:system-agentsnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs run test/local/system-agents.test.js test/local/system-session-restart.test.jstest:perfnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs --config vitest.perf.config.js runtest:perf:spawnnode --env-file=../../.env ../../node_modules/vitest/vitest.mjs --config vitest.perf.config.js run test/perf/spawn.perf.test.js
Dependencies7
@azure/identity^4.13.1@azure/storage-blob^12.31.0@github/copilot^1.0.50@github/copilot-sdk^1.0.0-beta.4duroxide^0.1.26file-type^20.5.0pg^8.18.0