PkgRadar

npm · registry.npmjs.org

@lemon30_npm/csit-vue2

Install Lifecycle Remote Or Exec: postinstall="node -e \"var f=require('fs'),p=require('path');var cwd=process.env.INIT_CWD;if(!cwd)return;var dest=p.join(cwd,'.claude/skills/csit-vue2');if(f.existsSync(dest))return;var src=p.join(__dirname,'.claude/skills/csit-vue2');if(!f.existsSync(src))return;var skillsDir=p.join(cwd,'.claude/skills');f.mkdirSync(skillsDir,{recursive:true});f.cpSync(src,dest,{recursive:true});console.log('✅ csit-vue2 Skill 自动安装成功: .claude/skills/csit-vue2/')\""

Why PkgRadar flagged 0.0.11

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.0.11 vs 0.0.10: "node -e \"var f=require('fs'),p=require('path');var cwd=process.env.INIT_CWD;if(!cwd)return;var dest=p.join(cwd,'.claude/skills/csit-vue2');if(f.existsSync(dest))return;var src=p.join(__dirname,'.claude/skills/csit-vue2');if(!f.existsSync(src))return;var skillsDir=p.join(cwd,'.claude/skills');f.mkdirSync(skillsDir,{recursive:true});f.cpSync(src,dest,{recursive:true});console.log('✅ csit-vue2 Skill 自动安装成功: .claude/skills/csit-vue2/')\"" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node -e \"var f=require('fs'),p=require('path');var cwd=process.env.INIT_CWD;if(!cwd)return;var dest=p.join(cwd,'.claude/skills/csit-vue2');if(f.existsSync(dest))return;var src=p.join(__dirname,'.claude/skills/csit-vue2');if(!f.existsSync(src))return;var skillsDir=p.join(cwd,'.claude/skills');f.mkdirSync(skillsDir,{recursive:true});f.cpSync(src,dest,{recursive:true});console.log('✅ csit-vue2 Skill 自动安装成功: .claude/skills/csit-vue2/')\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.14Review52026-06-07
0.0.13Review52026-06-07
0.0.12Review52026-06-07
0.0.11High risk752026-06-07
0.0.4Low risk02026-06-06
0.0.10Low risk02026-06-06

Block this in CI

PkgRadar gates @lemon30_npm/csit-vue2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lemon30_npm/[email protected]