PkgRadar

Package evidence

uuv-assistant-ai==1.9.1

Credential File Packaged: uuv_assistant_ai-1.9.1/.env

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
11
First published
Mar 2026
Publisher
Louis Fredice NJAKO MOLOM, Stanley SERVICAL

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["uuv-assistant-ai==1.9.1"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["uuv-assistant-ai==1.9.1"],"fail_on":"high"}'
Artifact bytes379,079
Previous versionnone
Published2026-05-27T08:01:12
SHA-2566f17255af82384ccd733ffb0f5c41cb5b6f08e92e0c9cc59eaf42c23848f75e2

Why flagged

What the scanner saw

Credential File Packaged: uuv_assistant_ai-1.9.1/.env

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
35Score
1.9.1Version
Status history (1 event)
  1. newavailable · risk high · score 35 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential File Packageduuv_assistant_ai-1.9.1/.envuuv_assistant_ai-1.9.1/.env35