What is the problem this feature would solve?
It would stop crypto miners and malware updates from NPM. You have to agree to use ENV vars, sub process or HTTP serving
What is the feature you are proposing to solve the problem?
A --allow-[permission] and a y or n prompt to ask if it can use things.
What alternatives have you considered?
No response