PkgRadar

npm · registry.npmjs.org

@bgx4k3p/huly-mcp-server

Native Addon Gyp Action: binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)

Why PkgRadar flagged 2.2.4

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.2.4 vs 2.2.3: "node scripts/patch-sdk.mjs" · package.json
highNative Addon Gyp Actionbinding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle) · package/node_modules/msgpackr-extract/binding.gyp

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.4High risk802026-06-10
2.4.3Low risk02026-06-02
2.4.1Low risk02026-05-29
2.4.2Low risk02026-05-29
2.3.0Review82026-05-28
2.4.0Review72026-05-28
2.2.5Review172026-05-24

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Related campaigns

Block this in CI

PkgRadar gates @bgx4k3p/huly-mcp-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bgx4k3p/[email protected]
@bgx4k3p/huly-mcp-server — npm security scan | PkgRadar