The same is true of `npm install`. Custom lifecycle scripts can be run during the install process.
Adding "ignore-scripts=true" to your ~/.npmrc helps here.
Although true, it is the same for npm or yarn too. There's no real solution to the typo problem, and it's not npx specific.
In a team environment npm or yarn configuration would go through peer review, whereas getting used to typing npx increases your chances of falling victim to a typo.
The npx part is only to setup the project, which is making a package.json and a src directory.