no-npm — block npm/npx/yarn, pnpm only
Why this skill exists
The npm ecosystem went through a series of major supply-chain attacks
(Shai-Hulud Sep 2025, Shai-Hulud 2.0 Nov 2025, Mini Shai-Hulud May 2026,
PackageGate Jan 2026). pnpm v11+ blocks lifecycle scripts by default
(strictDepBuilds) and delays installation of fresh versions by 24 hours
(minimumReleaseAge: 1440) — that closes the primary attack vectors.
Global user decision: no npm/npx/yarn in this environment.
What to
[Description truncada. Veja o README completo no GitHub.]