Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- Apr 2026
- Publisher
- bradkinnard
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Credential file access: matched ".npmrc"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 5 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Credential file access | package/dist/src/audit/cheat-detector/diff-walker.js | matched ".npmrc" | 5 |
Manifest
Package metadata
Scripts59
agent-incidence:arbitertsc -p tsconfig.build.json && node dist/scripts/real-prs/arbiter-agent-prs.jsagent-incidence:audittsc -p tsconfig.build.json && node dist/scripts/real-prs/audit-agent-prs.jsagent-incidence:fetchtsc -p tsconfig.build.json && node dist/scripts/real-prs/fetch-agent-prs.jsagent-incidence:fulltsc -p tsconfig.build.json && node dist/scripts/real-prs/fetch-agent-prs.js && node dist/scripts/real-prs/audit-agent-prs.js && node dist/scripts/real-prs/arbiter-agent-prs.js && node dist/scripts/real-prs/build-agent-incidence-report.jsagent-incidence:reporttsc -p tsconfig.build.json && node dist/scripts/real-prs/build-agent-incidence-report.jsbadges:checktsc -p tsconfig.build.json && node dist/scripts/badges/regen-badges.js --checkbadges:regentsc -p tsconfig.build.json && node dist/scripts/badges/regen-badges.jsbenchmarks:baselinetsc -p tsconfig.build.json && node dist/scripts/benchmarks/run-baseline.jsbenchmarks:fulltsc -p tsconfig.build.json && node dist/scripts/benchmarks/full.jsbenchmarks:oracletsc -p tsconfig.build.json && node dist/scripts/benchmarks/run-oracle.jsbenefit:arbitertsc -p tsconfig.build.json && node dist/scripts/real-prs/run-arbiter-dual.jsbenefit:audittsc -p tsconfig.build.json && node dist/scripts/real-prs/run-audit-v2.jsbenefit:differentialtsc -p tsconfig.build.json && node dist/scripts/real-prs/run-differential.jsbenefit:fetchtsc -p tsconfig.build.json && node dist/scripts/real-prs/fetch-clean-v2.jsbenefit:fulltsc -p tsconfig.build.json && node dist/scripts/real-prs/benefit-full.jsbenefit:minetsc -p tsconfig.build.json && node dist/scripts/real-prs/mine-regressions.jsbenefit:reporttsc -p tsconfig.build.json && node dist/scripts/real-prs/build-benefit-report.jsbenefit:venntsc -p tsconfig.build.json && node dist/scripts/real-prs/differential-venn.jsblock-eligibility:calibratetsc -p tsconfig.build.json && node dist/scripts/gate/run-trigger-calibration.jsblock-eligibility:computetsc -p tsconfig.build.json && node dist/scripts/gate/compute-block-eligibility.jsblock-eligibility:fulltsc -p tsconfig.build.json && node dist/scripts/gate/run-trigger-calibration.js && node dist/scripts/gate/compute-block-eligibility.jsblock-policy:checknode dist/scripts/gate/check-block-policy.jsbuildtsc -p tsconfig.build.json && node scripts/copy-non-ts-assets.js && node -e "require('fs').chmodSync('dist/src/cli.js', 0o755)"build:dockertsc -p tsconfig.docker.json && node scripts/copy-non-ts-assets.js && node -e "require('fs').chmodSync('dist/src/cli.js', 0o755)"calibrate:judgetsc -p tsconfig.build.json && node dist/scripts/oracle/calibrate-judge.jscleannode -e "require('fs').rmSync('dist',{recursive:true,force:true})"corpus:collect-negativestsc -p tsconfig.build.json && node dist/scripts/corpus/collect-negatives.jscorpus:collect-realtsc -p tsconfig.build.json && node dist/scripts/corpus/collect-real.jscorpus:generatetsc -p tsconfig.build.json && node dist/scripts/corpus/generate-v10.jscorpus:score-realtsc -p tsconfig.build.json && node dist/scripts/corpus/score-real.js- …and 29 more.
Dependencies6
@anthropic-ai/sdk^0.95.1@octokit/rest^20ajv^8.20.0js-yaml^4.1.1parse-diff^0.12.0typescript^5.9.3