PkgRadar

npm · registry.npmjs.org

@usejarvis/brain

Install Lifecycle Suppresses Failure: postinstall="node scripts/ensure-bun.cjs && (bun run copy:models 2>/dev/null || true)"

Why PkgRadar flagged 0.5.4

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/ensure-bun.cjs && (bun run copy:models 2>/dev/null || true)" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0Review12026-06-11
0.5.4High risk302026-06-10
0.6.1Review12026-06-01
0.6.0Review32026-05-28

Block this in CI

PkgRadar gates @usejarvis/brain (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @usejarvis/[email protected]