Install script firewall for npm - default-deny lifecycle scripts with explicit, reviewable allowlists