Loading the latest scan…
PyPI · pypi.org
Credential file access, Python Bun Js Exec, Py Runtime Base64 Decode +4 more
Why PkgRadar flagged 0.17.0.post1
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | — |
| medium | Python Bun Js Exec | — |
| medium | Python Bun Js Exec | — |
| medium | Python Bun Js Exec | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
| medium | Py Runtime Base64 Decode | — |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.17.0.post1 | High risk | 283 | 2026-07-03 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi redyuan43-hermes-agent==0.17.0.post1