PkgRadar

npm · registry.npmjs.org

agentgui

Install Lifecycle Suppresses Failure: postinstall="node scripts/patch-fsbrowse.js && node scripts/copy-vendor.js && (cd node_modules/better-sqlite3 && node-gyp rebuild 2>/dev/null) || true"

Why PkgRadar flagged 1.0.945

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/patch-fsbrowse.js && node scripts/copy-vendor.js && (cd node_modules/better-sqlite3 && node-gyp rebuild 2>/dev/null) || true" · package.json
mediumRemote Dependency Specdependencies.ccsniff="github:AnEntrypoint/ccsniff#main" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.945High risk372026-06-03
1.0.944High risk372026-06-03
1.0.943High risk372026-06-03
1.0.941High risk372026-06-03
1.0.942High risk372026-06-03
1.0.938High risk372026-06-03
1.0.939High risk372026-06-03
1.0.937High risk372026-06-03
1.0.935High risk372026-06-03
1.0.936High risk372026-06-03

Block this in CI

PkgRadar gates agentgui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]