Lifecycle script
A command a package tells the package manager to run automatically, for example straight after it is installed.
npm packages can declare scripts such as preinstall, install and postinstall, and by default npm runs them as part of installing the package, with the privileges of whoever ran the install. Nothing has to be imported or started for the code to run.
Most are harmless build steps. They are also the most direct way for a malicious package to act before anybody has looked at it, which is why installing with scripts disabled is a common precaution.
It is the point at which reading a package stops being enough: installing it can run code before you ever call a tool.
Thinking an MCP server can only act when a tool is called. Its install script has already run by then.
Related terms
See Lifecycle script on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue