PkgRadar

npm · registry.npmjs.org

@dezycro-ai/agent-plugin

Install Lifecycle Suppresses Failure: postinstall="[ -f dist/cli/install.js ] && node dist/cli/install.js || true"

Why PkgRadar flagged 2.5.0

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="[ -f dist/cli/install.js ] && node dist/cli/install.js || true" · package.json
mediumNew Account With Lifecycle Hookpackage first published 12 day(s) ago, 9 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.0High risk252026-06-12
2.4.0High risk252026-06-12
2.3.1High risk252026-06-11
2.3.0High risk252026-06-11
2.2.0High risk252026-06-10
2.1.2Review52026-06-06
2.1.1Review52026-06-03
2.1.0Review52026-06-02
2.0.0Review52026-05-31

Block this in CI

PkgRadar gates @dezycro-ai/agent-plugin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dezycro-ai/[email protected]