PkgRadar

npm · registry.npmjs.org

@agent-qofeno/agentx-cli

Native Binary Main Entry: main/bin entry points to a compiled binary: bin entry

Why PkgRadar flagged 1.2.2

SeveritySignalEvidence
highNative Binary Main Entrymain/bin entry points to a compiled binary: bin entry · package.json
highNew Lifecycle Script Vs Previouspostinstall added in 1.2.2 vs 0.0.0-main-202606200928: "node ./postinstall.mjs" · package.json
mediumNew Account With Lifecycle Hookpackage first published 0 day(s) ago, 7 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.2High risk902026-06-20
0.0.0-main-202606200925High risk452026-06-20
0.0.0-main-202606200928High risk452026-06-20
0.0.0-main-202606200920High risk452026-06-20
0.0.0-main-202606200834High risk452026-06-20
0.0.0-main-202606200807High risk502026-06-20
0.0.0-main-202606200822High risk502026-06-20

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Related campaigns

Block this in CI

PkgRadar gates @agent-qofeno/agentx-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agent-qofeno/[email protected]