That doesn't help you if anyone on your team installs a vscode plugin which uses npm in the background & executes postinstall scripts.