PkgRadar

npm Ā· registry.npmjs.org

@diagrammo/dgmo

Install Lifecycle Remote Or Exec: postinstall="node -e \"console.log('\\nšŸ’” Claude Code user? Run: dgmo --install-claude-skill\\n')\""

Why PkgRadar flagged 0.29.0

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"console.log('\\nšŸ’” Claude Code user? Run: dgmo --install-claude-skill\\n')\"" Ā· package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.29.0High risk242026-06-13
0.19.0High risk242026-06-13
0.20.1High risk242026-06-13
0.28.0High risk242026-06-10
0.18.1High risk352026-06-10
0.18.0High risk242026-06-10
0.27.0High risk242026-06-10
0.26.0High risk242026-06-10
0.25.5High risk242026-06-10
0.25.4High risk242026-06-10
0.25.2High risk242026-06-10
0.25.3High risk242026-06-10
0.25.0High risk242026-06-10
0.24.0High risk242026-06-10
0.23.0High risk242026-06-10
0.22.0High risk242026-06-10
0.21.1High risk242026-06-10
0.21.0High risk242026-06-10
0.20.3High risk242026-06-10
0.20.2High risk242026-06-10
0.20.0High risk242026-06-10
0.17.0Review252026-05-28

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @diagrammo/dgmo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @diagrammo/[email protected]