PkgRadar

Package evidence

[email protected]

Remote Payload: matched "raw.githubusercontent.com"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
484
Versions published
196
First published
Jan 2026
Publisher
tomer_wogi

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Publishertomer_wogi
Artifact bytes2,481,950
Previous version2.33.0
Published2026-05-23T06:48:13.766Z
SHA-256181338610678229083530b8d8e61cdbe55af64c6281ad46018f61e66cf2a5c22

Why flagged

What the scanner saw

Remote Payload: matched "raw.githubusercontent.com"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
179Score
2.34.1Version
Status history (1 event)
  1. newavailable · risk review · score 179 · status changed

Evidence

Static findings

47 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/.workflow/bridges/claude-bridge.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/scripts/flow-figma-mcp-server.jsmatched "curl "12
mediumRemote Payloadpackage/lib/skill-registry.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/scripts/hooks/core/worker-continuation-gate.jsmatched "curl "12
mediumRemote Payloadpackage/scripts/hooks/core/worker-tool-first-gate.jsmatched "curl "12
mediumRemote Payloadpackage/lib/workspace-channel-server.jsmatched "curl "12
mediumRemote Payloadpackage/scripts/hooks/core/workspace-stop-gates.jsmatched "curl "12
mediumRemote Payloadpackage/lib/workspace.jsmatched "curl "12
Show all 47 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumRemote Payloadpackage/.workflow/bridges/claude-bridge.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/scripts/flow-figma-mcp-server.jsmatched "curl "12
mediumRemote Payloadpackage/lib/skill-registry.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/scripts/hooks/core/worker-continuation-gate.jsmatched "curl "12
mediumRemote Payloadpackage/scripts/hooks/core/worker-tool-first-gate.jsmatched "curl "12
mediumRemote Payloadpackage/lib/workspace-channel-server.jsmatched "curl "12
mediumRemote Payloadpackage/scripts/hooks/core/workspace-stop-gates.jsmatched "curl "12
mediumRemote Payloadpackage/lib/workspace.jsmatched "curl "12
lowCredential file accesspackage/scripts/flow-damage-control.jsmatched ".ssh"5
lowObfuscationpackage/scripts/flow-assumption-detector.jsmatched "\\u25CF"3
lowObfuscationpackage/scripts/flow-capture-gate.jsmatched "\\u25CB"3
lowObfuscationpackage/scripts/flow-cascade-completion.jsmatched "\\u2713"3
lowObfuscationpackage/scripts/flow-completion-truth-gate.jsmatched "\\u25CB"3
lowObfuscationpackage/scripts/flow-config-defaults.jsmatched "\\u0027"3
lowObfuscationpackage/scripts/flow-config-loader.jsmatched "\\u26a0"3
lowObfuscationpackage/scripts/flow-conflict-resolver.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-damage-control.jsmatched "\\x00"3
lowObfuscationpackage/scripts/flow-done-gates.jsmatched "\\u25CB"3
lowObfuscationpackage/scripts/flow-done-report.jsmatched "\\u2501"3
lowObfuscationpackage/scripts/flow-eval-calibration.jsmatched "Eval("3
lowObfuscationpackage/scripts/flow-eval.jsmatched "Eval("3
lowObfuscationpackage/scripts/flow-long-input-cli.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-long-input-language.jsmatched "\\u0400"3
lowObfuscationpackage/scripts/flow-morning.jsmatched "\\u2022"3
lowObfuscationpackage/scripts/flow-orchestrate-validation.jsmatched "\\u200B"3
lowObfuscationpackage/scripts/flow-output.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-parallel.jsmatched "\\u2588"3
lowObfuscationpackage/scripts/flow-progress-tracker.jsmatched "\\u2588"3
lowObfuscationpackage/scripts/flow-progress.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-roadmap.jsmatched "\\x00"3
lowObfuscationpackage/scripts/flow-security.jsmatched "\\x00"3
lowObfuscationpackage/scripts/flow-start.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-step-review.jsmatched "eval("3
lowObfuscationpackage/scripts/flow-story-gates.jsmatched "\\x00"3
lowObfuscationpackage/scripts/flow-strict-adherence.jsmatched "\\x00"3
lowObfuscationpackage/scripts/flow-test-integrity.jsmatched "\\u20AC"3
lowObfuscationpackage/scripts/flow-utils.jsmatched "\\u2014"3
lowObfuscationpackage/scripts/flow-verify.jsmatched "eval("3
lowObfuscationpackage/scripts/flow-wiring-verifier.jsmatched "\\u2713"3
lowObfuscationpackage/scripts/flow-workspace-summary.jsmatched "Buffer.from(s, 'base64"3
lowObfuscationpackage/lib/installer.jsmatched "\\x1b"3
lowObfuscationpackage/lib/commands/login.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/postinstall.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/hooks/core/pre-tool-orchestrator.jsmatched "\\u26d4"3
lowObfuscationpackage/scripts/preuninstall.jsmatched "\\x1b"3
lowObfuscationpackage/scripts/flow-review-passes/security.jsmatched "eval("3
lowObfuscationpackage/lib/workspace-routing.jsmatched "\\u2713"3