PkgRadar

npm · registry.npmjs.org

cyrus-mcp-tools

Install Lifecycle Remote Or Exec: postinstall="node -e \"try { require('fs').chmodSync('./dist/index.js', '755') } catch (e) {}\""

Why PkgRadar flagged 0.1.2

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try { require('fs').chmodSync('./dist/index.js', '755') } catch (e) {}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.64-test.3Low risk02026-06-10
0.2.64-test.2Low risk02026-06-10
0.2.64-test.1Low risk02026-06-10
0.1.2High risk242026-06-10
0.2.0High risk242026-06-10
0.3.0High risk752026-06-10
0.2.64-test.0Low risk02026-06-10
0.2.63Low risk02026-06-09
0.2.62Low risk02026-06-02
0.2.61Low risk02026-06-01
0.2.60Low risk02026-05-29
0.2.59Low risk02026-05-29
0.2.57Low risk02026-05-27
0.2.58Low risk02026-05-27

Block this in CI

PkgRadar gates cyrus-mcp-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]