Healthy and suitable to use. It has frequent releases, active work from multiple contributors, organization backing, and verified build provenance; the main caveats are limited security tooling and a small registry publisher list.
86%
Total Score
90
50
95
80
100
Nine runtime dependencies create a meaningful dependency surface, including native or operationally significant packages such as sharp, but the profile is not excessive for an SDK.
Only one registry account has publish access, which is a modest publishing concentration risk; organization backing and strong repository activity provide meaningful operational support.
The repository uses TypeScript, Turbo, and npm scripts, but reports no security scanning tools; the missing scanning is a transparency and assurance gap, not evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Two workflows lack top-level permissions and one release workflow requests top-level write access; this is a workflow-hardening gap, though no dangerous workflow behavior was detected.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-666371 @argos-ci/core is vulnerable to OS Command Injection in versions 0.1.0 - 6.2.0. | 0.1.0 - 6.2.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
tmp Version ^0.2.7 | — | — |
debug Version ^4.4.3 | — | — |
sharp Version ^0.35.3 | — | — |
convict Version ^6.2.5 | — | — |
p-retry Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.