PkgRadar

npm · registry.npmjs.org

@11agents/cli

Install-time lifecycle script: postinstall="node scripts/mobile-postinstall.js"

Why PkgRadar flagged 0.1.25

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.25 vs 0.1.24: "node scripts/mobile-postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.41Review52026-06-11
0.1.40Review52026-06-11
0.1.39Review52026-06-11
0.1.38Review52026-06-11
0.1.37Review52026-06-11
0.1.35Review52026-06-11
0.1.36Review52026-06-11
0.1.34Review52026-06-10
0.1.33Review52026-06-10
0.1.32Review52026-06-10
0.1.31Review52026-06-10
0.1.30Review52026-06-10
0.1.28Review52026-06-10
0.1.29Review52026-06-10
0.1.27Review52026-06-10
0.1.25High risk452026-06-10
0.1.26Review52026-06-10
0.1.24Low risk02026-06-09
0.1.23Low risk02026-06-09
0.1.19Low risk02026-06-09
0.1.22Low risk02026-06-09
0.1.21Low risk02026-06-04
0.1.20Low risk02026-06-04
0.1.18Low risk02026-06-04
0.1.17Low risk02026-06-04
0.1.16Low risk02026-06-04
0.1.15Low risk02026-06-03
0.1.14Low risk02026-06-03
0.1.13Low risk02026-06-03
0.1.12Low risk02026-06-03
0.1.11Low risk02026-06-03
0.1.10Low risk02026-06-03
0.1.9Low risk02026-06-02
0.1.8Low risk02026-06-02
0.1.3Low risk02026-06-02
0.1.2Low risk02026-06-01
0.1.1Low risk02026-06-01

Block this in CI

PkgRadar gates @11agents/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @11agents/[email protected]