Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 6
- First published
- May 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "api.telegram.org/bot"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 5 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/node-backend/lib/channels.mjs | matched "api.telegram.org/bot" | 12 |
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/node-backend/lib/channels.mjs | matched "api.telegram.org/bot" | 12 |
| low | Messenger Bot Endpoint | package/node-backend/lib/channels.mjs | matched "api.telegram.org/bot" — messenger-bot URL without exfil context (likely a notification handler) | 5 |
Manifest
Package metadata
Scripts26
buildtsc && vite builddemo:remotionremotion studio src/remotion/index.tsdemo:render:competitiveremotion render src/remotion/index.ts CompetitiveAnalysisArtifact renders/competitive-analysis-artifact.mp4demo:render:connectremotion render src/remotion/index.ts ConnectProductToGitHub renders/connect-product-github.mp4demo:render:marketing-suiteremotion render src/remotion/index.ts ProductOSMarketingSuite renders/productos-marketing-suite.mp4demo:render:workflowremotion render src/remotion/index.ts WorkflowFromCompetitiveIntel renders/workflow-competitive-intel.mp4devnpm run dev:nodedev:nodeconcurrently -k -p "[{name}]" -n "vite,node-server" -c "cyan.bold,green.bold" "vite" "npm run dev:server:node"dev:node-prototypenode scripts/run-node-prototype-dev.mjsdev:server:cinode scripts/run-dev-server-ci.mjsdev:server:nodePRODUCTOS_NODE_SERVER_PORT=51423 node node-backend/server.mjsgenerate-creditsnode scripts/generate-credits.cjsprepublishOnlynpm run buildstartnpm run build && npm run dev:server:nodestopnode scripts/stop-dev.jstest:backendnode --test node-backend/tests/*.test.mjs node-backend/tests/services/*.test.mjs tests/*.test.mjstest:channelsnode --test tests/channel-settings.test.mjstest:e2eplaywright testtest:e2e:cinode scripts/run-e2e-ci.mjstest:e2e:headedplaywright test --headedtest:e2e:uiplaywright test --uitest:guardrailsnode --test tests/artifact-quality.test.mjstest:integration:token-savernode --test tests/token-saver.integration.test.mjstest:mvp:personal-pmnode --test tests/artifact-quality.test.mjs tests/starter-pack.test.mjs tests/token-saver.integration.test.mjstest:starter-packnode --test tests/starter-pack.test.mjstest:unit:optimizernode --test tests/workflow-optimizer.unit.test.mjs
Dependencies37
@radix-ui/react-context-menu2.2.16@radix-ui/react-dialog1.1.15@radix-ui/react-icons1.3.2@radix-ui/react-menubar1.1.16@radix-ui/react-select2.2.6@radix-ui/react-toast1.2.15@tiptap/extension-bubble-menu3.22.4@tiptap/extension-floating-menu3.22.4@tiptap/extension-link3.22.4@tiptap/extension-placeholder3.22.4@tiptap/extension-table3.22.4@tiptap/extension-table-cell3.22.4@tiptap/extension-table-header3.22.4@tiptap/extension-table-row3.22.4@tiptap/markdown3.22.4@tiptap/pm3.22.4@tiptap/react3.22.4@tiptap/starter-kit3.22.4@tiptap/suggestion3.22.4@types/tippy.js6.3.0@xyflow/react12.10.0chokidar^5.0.0class-variance-authority0.7.1clsx2.1.1date-fns4.1.0framer-motion12.29.0lucide-react0.263.1papaparse5.5.3pdf-parse^2.4.5pptxgenjs4.0.1- …and 7 more.