PkgRadar

Package evidence

[email protected]

Remote Dependency Spec: dependencies.@lloyal-labs/corpus-app="https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
9
Versions published
5
First published
May 2026
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Artifact bytes39,293
Previous version0.2.2
Published2026-06-12T16:14:50.017Z
SHA-2563ddaf8504916b13c4c325744d9218eabfd23781aa0251bd611747e0451f29860

Why flagged

What the scanner saw

Remote Dependency Spec: dependencies.@lloyal-labs/corpus-app="https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"

2 remote tarball(s) were followed statically.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
48Score
0.3.0Version
Status history (1 event)
  1. newavailable · risk high · score 48 · status changed

Evidence

Static findings

3 static · 2 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highRemote Dependency Specpackage.jsondependencies.@lloyal-labs/corpus-app="https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"12
highRemote Dependency Specpackage.jsondependencies.@lloyal-labs/web-app="https://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgz"12
highNew Remote Dependency Vs Previouspackage.jsondependencies.@lloyal-labs/corpus-app added in 0.3.0 vs 0.2.2: "https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"12
highNew Remote Dependency Vs Previouspackage.jsondependencies.@lloyal-labs/web-app added in 0.3.0 vs 0.2.2: "https://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgz"12
Show all 5 findings (low-signal and informational)
SeverityKindPathDetailPoints
highRemote Dependency Specpackage.jsondependencies.@lloyal-labs/corpus-app="https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"12
highRemote Dependency Specpackage.jsondependencies.@lloyal-labs/web-app="https://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgz"12
highNew Remote Dependency Vs Previouspackage.jsondependencies.@lloyal-labs/corpus-app added in 0.3.0 vs 0.2.2: "https://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz"12
highNew Remote Dependency Vs Previouspackage.jsondependencies.@lloyal-labs/web-app added in 0.3.0 vs 0.2.2: "https://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgz"12
lowObfuscation Densitypackage/dist/bundle.mjshigh encoded/escaped-token density0

Remote payloads

Followed remote artifacts

SourceURLRiskScoreSummary
dependencies.@lloyal-labs/corpus-apphttps://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgzlow0no remote findings
dependencies.@lloyal-labs/web-apphttps://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgzlow0no remote findings

Manifest

Package metadata

Scripts6
  • buildesbuild src/main.ts --bundle --platform=node --target=node22 --format=esm --packages=external --loader:.eta=text --outfile=dist/bundle.mjs --minify --legal-comments=none
  • build:watchesbuild src/main.ts --bundle --platform=node --target=node22 --format=esm --packages=external --loader:.eta=text --outfile=dist/bundle.mjs --watch
  • prepublishOnlynpm run build
  • smoketsx src/tui-ink/__bus-smoke.ts && tsx src/tui-ink/__reducer-smoke.ts && tsx src/tui-ink/__config-smoke.ts && tsx src/__download-smoke.ts && tsx src/__rundir-smoke.ts && tsx src/__clarify-trunk-smoke.ts
  • smoke:visualtsx src/tui-ink/__visual-smoke.tsx
  • startnpm run build && node bin/run.js
Dependencies12
  • @inkjs/ui^2.0.0
  • @lloyal-labs/corpus-apphttps://apps.lloyal.ai/v1/bundles/lloyal__corpus-1.1.0.tgz
  • @lloyal-labs/lloyal-agents^3.0.0
  • @lloyal-labs/lloyal.node^3.0.0
  • @lloyal-labs/rig^3.0.0
  • @lloyal-labs/sdk^3.0.0
  • @lloyal-labs/web-apphttps://apps.lloyal.ai/v1/bundles/lloyal__web-1.1.0.tgz
  • effection^4.0.2
  • eta^4.5.1
  • ignore^7.0.5
  • ink^7.0.1
  • react^19.2.5