PkgRadar

npm · registry.npmjs.org

@kidsinai/kids-opencode

Install Lifecycle Suppresses Failure: postinstall="sh ./scripts/postinstall.sh || true"

Why PkgRadar flagged 0.0.15

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="sh ./scripts/postinstall.sh || true" · package.json
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 3 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.15High risk282026-06-10
0.0.25High risk282026-06-10
0.0.26High risk282026-06-10
0.0.24High risk282026-06-10
0.0.23High risk282026-06-10
0.0.21High risk282026-06-10
0.0.22High risk402026-06-10
0.0.20High risk282026-06-10
0.0.19High risk282026-06-10
0.0.18High risk282026-06-10
0.0.17High risk402026-06-10
0.0.16High risk282026-06-10
0.0.14High risk282026-06-10
0.0.13High risk282026-06-10

Block this in CI

PkgRadar gates @kidsinai/kids-opencode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kidsinai/[email protected]