PkgRadar

npm · registry.npmjs.org

@evolvconsulting/evolv-coder-kit

Install Lifecycle Remote Or Exec: postinstall="node -e \"if(process.env.npm_config_global==='true'){console.log('\\n Run: evolv-coder-kit\\n')}\""

Why PkgRadar flagged 0.9.0

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"if(process.env.npm_config_global==='true'){console.log('\\n Run: evolv-coder-kit\\n')}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.6Low risk02026-06-12
0.9.0High risk402026-06-10
0.8.5High risk402026-06-10
0.8.4High risk402026-06-10
0.8.3High risk402026-06-10
0.8.2High risk402026-06-10
0.8.1Review102026-05-28
0.7.4Review102026-05-26
0.8.0Review102026-05-26

Block this in CI

PkgRadar gates @evolvconsulting/evolv-coder-kit (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @evolvconsulting/[email protected]