Package evidence
[email protected]
Install-time lifecycle script: postinstall="echo '\\n maya-deck installed!\\n Run: npx maya typescript\\n Compat: npx maya-install typescript\\n Docs: https://github.com/limbuslabteam/Maya\\n'"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- Jun 2026
- Publisher
- mayadev
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="echo '\\n maya-deck installed!\\n Run: npx maya typescript\\n Compat: npx maya-install typescript\\n Docs: https://github.com/limbuslabteam/Maya\\n'"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 5 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="echo '\\n maya-deck installed!\\n Run: npx maya typescript\\n Compat: npx maya-install typescript\\n Docs: https://github.com/limbuslabteam/Maya\\n'" | 5 |
| low | Large Javascript Payload | package/agentshield/index.mjs | 2059781 bytes | 0 |
Manifest
Package metadata
Scripts29
build:opencodenode scripts/build-opencode.jscatalog:checknode scripts/ci/catalog.js --textcatalog:syncnode scripts/ci/catalog.js --write --textclawnode scripts/claw.jscommand-registry:checknode scripts/ci/generate-command-registry.js --checkcommand-registry:generatenode scripts/ci/generate-command-registry.jscommand-registry:writenode scripts/ci/generate-command-registry.js --writecoveragec8 --all --include="scripts/**/*.js" --check-coverage --lines 80 --functions 80 --branches 80 --statements 80 --reporter=text --reporter=lcov node tests/run-all.jsdashboardpython3 ./maya_dashboard.pydiscussion:auditnode scripts/discussion-audit.jsharness:adaptersnode scripts/harness-adapter-compliance.jsharness:auditnode scripts/harness-audit.jslinteslint . && markdownlint '**/*.md' --ignore node_modulesmayanode scripts/maya.jsobservability:readynode scripts/observability-readiness.jsoperator:dashboardnode scripts/operator-readiness-dashboard.jsorchestrate:statusnode scripts/orchestration-status.jsorchestrate:tmuxnode scripts/orchestrate-worktrees.jsorchestrate:workerbash scripts/orchestrate-codex-worker.shplatform:auditnode scripts/platform-audit.jspostinstallecho '\n maya-deck installed!\n Run: npx maya typescript\n Compat: npx maya-install typescript\n Docs: https://github.com/limbuslabteam/Maya\n'prepacknpm run build:opencodepreview-pack:smokenode scripts/preview-pack-smoke.jsrelease:approval-gatenode scripts/release-approval-gate.jsrelease:video-suitenode scripts/release-video-suite.jssecurity:advisory-sourcesnode scripts/ci/supply-chain-advisory-sources.jssecurity:agentshieldnode agentshield/index.mjssecurity:ioc-scannode scripts/ci/scan-supply-chain-iocs.jstestnode scripts/ci/check-unicode-safety.js && node scripts/ci/validate-agents.js && node scripts/ci/validate-commands.js && node scripts/ci/validate-rules.js && node scripts/ci/validate-skills.js && node scripts/ci/validate-hooks.js && node scripts/ci/validate-install-manifests.js && node scripts/ci/validate-no-personal-paths.js && npm run catalog:check && npm run command-registry:check && node tests/run-all.js
Dependencies4
@anthropic-ai/claude-agent-sdk^0.3.162@iarna/toml^2.2.5ajv^8.20.0sql.js^1.14.1