PkgRadar

npm · registry.npmjs.org

crewly

Install Lifecycle Suppresses Failure: postinstall="(npm rebuild node-pty --build-from-source 2>/dev/null || npm rebuild node-pty 2>/dev/null || true) && (npm rebuild better-sqlite3 2>/dev/null || true)"

Why PkgRadar flagged 1.11.6

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="(npm rebuild node-pty --build-from-source 2>/dev/null || npm rebuild node-pty 2>/dev/null || true) && (npm rebuild better-sqlite3 2>/dev/null || true)" · package.json
mediumRemote Payloadmatched "curl " · package/dist/backend/backend/src/services/browser/chrome-discovery.service.js
mediumRemote Payloadmatched "curl " · package/config/skills/_common/complete-body-shape.test.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/core/create-intent-tasks/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/core/decompose-intent/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/core/update-intent-task/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/marketing/submit-for-approval/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/screenshot-compare/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/transcribe-audio/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/agent/xiaoyuzhoufm-transcript/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/orchestrator/decompose-mission/execute.sh
mediumRemote Payloadmatched "curl " · package/config/skills/orchestrator/decompose-okr/execute.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.12.1Review652026-06-12
1.12.0Review652026-06-12
1.11.6High risk632026-06-10
1.11.5High risk632026-06-10
1.11.4High risk632026-06-10
1.11.3High risk632026-06-10
1.11.2High risk632026-06-10
1.11.1High risk632026-06-10
1.11.0High risk632026-06-10
1.10.0High risk632026-06-10
1.9.0High risk632026-06-10
1.8.7High risk632026-06-10
1.8.8High risk632026-06-10
1.8.13High risk632026-06-10
1.8.12High risk632026-06-10
1.8.11High risk632026-06-10
1.8.9High risk632026-06-10

Block this in CI

PkgRadar gates crewly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]