npm · registry.npmjs.org
@agent-pattern-labs/software-contract-forge
Install-time lifecycle script: postinstall="node bin/sync.mjs"
Why PkgRadar flagged 0.1.8
| Severity | Signal | Evidence |
|---|---|---|
| high | Install-time lifecycle script | postinstall="node bin/sync.mjs" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.8 | Review | 5 | 2026-05-25 |
0.1.9 | Review | 5 | 2026-05-25 |
0.1.5 | Review | 5 | 2026-05-25 |
0.1.6 | Review | 5 | 2026-05-25 |
0.1.14 | Review | 5 | 2026-05-25 |
0.1.13 | Review | 5 | 2026-05-24 |
Related campaigns
- razroo — 8 releases, max score 33
- install_lifecycle_script:postinstall="node bin/sync.mjs" — 8 releases, max score 33
Block this in CI
pkgradar gate --ecosystem npm @agent-pattern-labs/[email protected]