DEV Community

Michael Kayode Onyekwere
Michael Kayode Onyekwere

Posted on

AGENTSCORE-2026-0008: `idea-manager` risk change detected

idea-manager updated from 2.4.5 to 2.5.2. Score changed 80/100 to 60/100 (-20). Risk: MODERATE to ELEVATED. 4 findings.

Package

  • Name: idea-manager
  • Version: 2.4.5 to 2.5.2
  • Score: 80/100 to 60/100
  • Risk: MODERATE to ELEVATED

Findings

  • [LOW] install_script: Package has 'postinstall' script: node bin/postinstall.js
  • [MEDIUM] excessive_dependencies: Package has 26 runtime dependencies (high attack surface)
  • [HIGH] command_injection: Potential command injection: shell execution with template literal input
  • [LOW] no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: navskh

Full advisory: AGENTSCORE-2026-0008

Verdict API: curl https://agentscores.xyz/api/verdict?npm=idea-manager

Auto-published by AgentScore MCP security monitoring.

Top comments (0)