PkgRadar

npm · registry.npmjs.org

allagents

Install Lifecycle Remote Or Exec: prepare="bun run build && (test -d .git && bunx prek install -t pre-push || true)"

Why PkgRadar flagged 1.11.10-next.1

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execprepare="bun run build && (test -d .git && bunx prek install -t pre-push || true)" · package.json
highInstall Lifecycle Suppresses Failureprepare="bun run build && (test -d .git && bunx prek install -t pre-push || true)" · package.json
mediumLarge Javascript Payload2042177 bytes · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.12.0-next.1Low risk02026-06-01
1.11.10-next.1Review602026-05-25
1.11.9Review602026-05-25

Related campaigns

Block this in CI

PkgRadar gates allagents (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]