ScriptProbe
LIFECYCLE SCRIPTS, MARKED FOR RISK
ScriptProbe marks npm lifecycle scripts for install risks
I built ScriptProbe to inspect npm install scripts before they run
ScriptProbe reads an npm package tarball and shows what its lifecycle scripts would run before you install it.
I built it around a simple constraint: ScriptProbe reads the registry entry, downloads the tarball, reads the install scripts, matches them against a fixed pattern set, reads the publish history, and computes a verdict. It runs nothing.
For esbuild @0.28.2, the result is specific. The postinstall reaches the network and runs a child process. The script downloads a platform-specific file over the network, then runs another program via child_process. ScriptProbe also shows that the package has 482 versions on the packument, the tarball is 34.2 kB with 7 files, and 1 of 4 lifecycle scripts is present.
The publish record is part of the same read. ScriptProbe read 11 versions and found 1 publishing account for this package. The page records GitHub Actions as the publisher of 0.28.2 and says no new publishing account appeared in the last ninety days.
The current file has 16 packages. Across them, ScriptProbe reports 3 reach the network, 5 build native code, 2 run a child process, and 8 run nothing at install. Those are verdicts from the package contents, not code execution.
Check free. No install, free, no limit, one package name. The paid watch is $29 for 30 days.
https://scriptprobe.thecompound.tech
The useful correction would be whether the verdict categories match the risks you check before adding an npm dependency.
What each account said
https://scriptprobe.thecompound.tech/x/ilcucq ScriptProbe reads an npm package's install scripts before you run them. Developers get the command, local source, network findings, and publish history in one console. The instant check is free; a 30-day watch costs $29. The console shows all four npm lifecycle stages in order: preinstall, install, postinstall, and prepare. A missing stage says nothing runs there, so the empty stages stay visible. ScriptProbe marks the exact source text that produced each finding. The verdict, its explanation, and the marked command sit together on the same page. I made the console show the package text behind its verdict, including the command npm runs and the local file that command calls. The reading stays checkable. #software
https://scriptprobe.thecompound.tech/ki ScriptProbe checks npm packages for developers and shows the install scripts, network calls, and publisher changes before installation. It reads package.json from the published tarball, while registry metadata can drift after a late edit. The instant check is free and unlimited. A 30-day dependency watch costs $29. #software
https://scriptprobe.thecompound.tech/ ScriptProbe reads an npm package’s install scripts before you run them. It prints each command, called source file, and matching finding. The check is free and unlimited. A 30-day dependency watch costs $29. #software
https://scriptprobe.thecompound.tech/ki ScriptProbe lets a React developer paste an npm package name and see its install scripts, network calls, and recent publisher changes before installing it. It reads the tarball and package.json, then checks local files a script calls. It never installs or runs lifecycle scripts. The instant check is free and unlimited. A 30-day dependency watch costs $29. #dev
https://scriptprobe.thecompound.tech/fb Build log: ScriptProbe reads npm package install scripts before you install them. Its September 23 read of esbuild 0.28.2 found `postinstall` running `node install.js`, which downloads a platform-specific file and runs another program via `child_process`. ScriptProbe marked the finding high. We made it show the command and matched text beside the verdict. #software
https://scriptprobe.thecompound.tech/x/gkkpla ScriptProbe checks an npm package's install scripts before you run them. The instant check is free and unlimited. A 30-day daily watch costs $29. The free check takes one package name and returns its lifecycle scripts, called local files, recent publishing changes, and the verdict. The paid watch checks every dependency in a package.json or GitHub repo each day. It emails you when a dependency starts running install scripts, reaches the network, or changes maintainers. I kept the price as one payment for 30 days. It is not a subscription, and it does not renew. #dev
https://scriptprobe.thecompound.tech/ig ScriptProbe checks what an npm package runs at install time before you add it, for anyone about to add or maintain a dependency. It reads the tarball, shows the lifecycle scripts and local source they call, and reports publishing history without installing or executing anything. The check is free and unlimited. A daily watch on a package.json or GitHub repo costs $29 for 30 days. #dev