Package evidence
[email protected]
Install Lifecycle Suppresses Failure: postinstall="node scripts/postinstall.cjs || exit 0"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 13
- Versions published
- 9
- First published
- May 2026
- Publisher
- muonroi
Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Install Lifecycle Suppresses Failure: postinstall="node scripts/postinstall.cjs || exit 0"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 25 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Install Lifecycle Suppresses Failure | package.json | postinstall="node scripts/postinstall.cjs || exit 0" | 20 |
| medium | New Account With Lifecycle Hook | package.json | package first published 37 day(s) ago, 9 total version(s), has lifecycle hook | 10 |
Show all 3 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Install Lifecycle Suppresses Failure | package.json | postinstall="node scripts/postinstall.cjs || exit 0" | 20 |
| medium | New Account With Lifecycle Hook | package.json | package first published 37 day(s) ago, 9 total version(s), has lifecycle hook | 10 |
| low | Install-time lifecycle script | package.json | postinstall="node scripts/postinstall.cjs || exit 0" | 5 |
Manifest
Package metadata
Scripts25
buildnode scripts/sync-version.cjs && tsc && node scripts/fix-extensions.cjs && node -e "require('fs').cpSync('src/models/catalog.json', 'dist/src/models/catalog.json', { recursive: true })"build:binarybun build --compile --outfile ./dist/muonroi-cli-standalone ./src/index.tsbuild:corecd packages/agent-harness-core && bun run buildclean:metagit clean -fdX -- .scratch chat-export-*.txt .ee-ingest-state.json .brain-*.tmp 2>/dev/null || echo 'clean:meta: no matching untracked ignored files or git unavailable'devnode scripts/sync-version.cjs && bun run src/index.tsee:ingest-bbbun run scripts/ingest-bb-to-ee.mtsformatbiome format src/format:fixbiome format --write src/lintbiome check src/lint:fixbiome check --fix src/lint:harness-skipsbun run scripts/check-harness-skips.tslint:harness-skips:strictbun run scripts/check-harness-skips.ts --strictlint:semanticbun scripts/check-semantic-wrap.tspostinstallnode scripts/postinstall.cjs || exit 0pre-commitlint-stagedpreparehuskystartbun run dist/index.jstestbunx vitest runtest:angularbunx vitest -c packages/agent-harness-angular/vitest.config.ts runtest:corebunx vitest run packages/agent-harness-core/__tests__/test:harnessbunx vitest -c vitest.harness.config.ts run tests/harness/test:harness-angularbunx vitest -c vitest.harness-angular.config.ts run tests/harness-angular/test:harness-reactbunx vitest -c packages/agent-harness-react/vitest.config.ts runtest:watchbunx vitesttypechecktsc --noEmit
Dependencies30
@ai-sdk/anthropic3.0.72@ai-sdk/google3.0.65@ai-sdk/mcp1.0.37@ai-sdk/openai3.0.54@ai-sdk/openai-compatible2.0.42@ai-sdk/provider3.0.9@ai-sdk/provider-utils4.0.24@modelcontextprotocol/sdk1.29.0@npmcli/arborist^9.4.3@opentui/core0.1.107@opentui/react0.1.107@qdrant/js-client-rest1.17.0ai6.0.169better-sqlite3^12.10.0commander^12.1.0diff^8.0.3fast-xml-parser^4.4.1gpt-tokenizer^3.4.0keytar7.9.0ollama-ai-provider-v21.5.5proper-lockfile^4.1.2react19.2.5ripgrep^0.3.1semver^7.7.4tree-sitter-python^0.25.0tree-sitter-typescript^0.23.2vscode-jsonrpc8.2.1vscode-languageserver-types3.17.5web-tree-sitter0.26.8zod^4.3.6