PkgRadar

npm · registry.npmjs.org

@poncho-ai/browser

Install Lifecycle Remote Or Exec: postinstall="node -e \"if(!process.env.CI&&!process.env.SERVERLESS)require('child_process').execSync('npx playwright install chromium',{stdio:'inherit'})\""

Why PkgRadar flagged 0.6.17

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"if(!process.env.CI&&!process.env.SERVERLESS)require('child_process').execSync('npx playwright install chromium',{stdio:'inherit'})\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.17High risk352026-06-04
0.6.18High risk352026-06-04

Block this in CI

PkgRadar gates @poncho-ai/browser (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @poncho-ai/[email protected]