JSPM

Found 1210 results for supply-chain

@appthreat/cdx-proto

Library to serialize/deserialize CycloneDX BOM with protocol buffers

  • v2.0.1
  • 65.27
  • Published

bluefairy

A standalone package freshness guard for uv and npm.

    • v0.0.31
    • 49.46
    • Published

    @blamejs/core

    The Node framework that owns its stack.

    • v0.15.0
    • 48.34
    • Published

    @blamejs/exceptd-skills

    AI security skills grounded in mid-2026 threat reality, not stale framework documentation. 51 skills, 11 catalogs (439 CVEs / 177 CWEs / 805 ATT&CK + ICS / 170 ATLAS / 468 D3FEND / 8888 RFCs), 35 jurisdictions, 10-class catalog gap detector + budget gate,

    • v0.16.25
    • 48.29
    • Published

    sha1-hulud-scanner

    Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data

    • v1.0.1
    • 43.60
    • Published

    muaddib-scanner

    Supply-chain threat detection & response for npm & PyPI/Python

    • v2.11.78
    • 42.74
    • Published

    @lateos/npm-scan

    Production-grade npm supply chain vulnerability scanner. Detects 100% of 3 real May 2026 supply chain campaigns (dependency confusion, obfuscation, impersonation) with 0% false positive rate on top 1,000 npm packages.

    • v1.2.9
    • 38.96
    • Published

    searoute-ts

    Shortest sea route between any two points on Earth. TypeScript library with the Eurostat 2025 maritime network, canal/strait restrictions (Suez, Panama, Bab-el-Mandeb…), vessel-draft gating, K-shortest alternatives, multi-leg waypoints, and ETA from vesse

    • v2.0.0
    • 38.12
    • Published

    cache-poisoning-pwn-demo

    Educational demo: a deliberately vulnerable npm package showing how GitHub Actions cache poisoning can produce a malicious release without stealing any credential. Do NOT use in production.

    • v0.1.32
    • 37.50
    • Published

    neural-trader

    High-performance neural trading system with complete NAPI API (178 functions), advanced CLI with interactive mode, GPU acceleration, real-time execution, multi-agent swarm coordination, neural networks, risk management, sports betting, syndicate collabora

    • v2.8.11
    • 36.72
    • Published

    @gkiely/safe-install

    Run npm installs with dependency lifecycle scripts disabled, then rebuild explicitly trusted dependencies.

    • v0.1.33
    • 36.67
    • Published

    supply-chain-attack

    Scan local package-manager state for known supply-chain attack indicators.

    • v0.1.10
    • 35.69
    • Published

    guardvibe

    Security infrastructure your AI can't be — deterministic, current past your model's training cutoff, whole-repo-aware, author-independent. Security MCP for vibe coding. 442 rules, 37 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered d

    • v3.18.0
    • 35.41
    • Published

    ai-trust

    Trust verification CLI for AI packages — check MCP servers, A2A agents, AI tools, and LLMs before you install

    • v0.7.5
    • 35.17
    • Published

    @safedep/pmg

    PMG - Package Manager Guard: protect developers from malicious packages

    • v0.18.1
    • 34.94
    • Published

    proof-of-commitment

    Supply chain security risk scorer for npm, PyPI, Cargo, and Go packages — behavioral signals that can't be faked

    • v1.25.0
    • 34.73
    • Published

    supply-chain-guard

    Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs

    • v5.2.30
    • 34.56
    • Published

    @kratex/cli

    Node.js supply-chain enforcement at install and at runtime. Policy-gated lifecycle scripts, caller-chain-attributed runtime hook.

    • v0.5.0
    • 34.26
    • Published

    leedab

    A local AI operating system that learns your operations and runs them with Artificial Beings. Across portals, ERPs, dashboards, inboxes, spreadsheets, and PDFs. On your hardware. Your data. No APIs.

      • v0.9.1
      • 34.24
      • Published

      pmsec

      Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, uv, and bundler.

      • v0.13.0
      • 33.92
      • Published

      @kosli/cli

      CLI client for reporting compliance events to https://kosli.com

      • v2.25.0
      • 33.11
      • Published

      @vionsec/cli

      VION Security CLI — secure-by-default installer for the VION agent across Claude Code, Blackbox AI, OpenAI Codex, and terminal.

      • v0.6.7
      • 32.99
      • Published

      @kratex/shared

      Policy schema, resolved-rule types, normalizer, and route contracts shared across Kratex components.

      • v0.5.0
      • 32.85
      • Published

      aminet

      CLI and GitHub Action for npm supply chain security reviews

      • v0.4.0
      • 32.70
      • Published

      ship-safe

      AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a

      • v9.3.2
      • 32.59
      • Published

      tip-verify

      CLI for verifying repository integrity roots against the TIP registry.

      • v0.2.6
      • 32.54
      • Published

      fad-checker

      Scan ALL Maven, npm, Yarn, Composer, Python, C#/.NET, Go & Ruby dependencies — plus embedded JARs (fat-jars/war/ear) — in a source tree ONE SHOT without mvn/python/etc — CVE (EPSS/KEV-prioritised), EOL, obsolete, outdated & licenses, with SBOM/CSAF/SARIF/

      • v2.2.4
      • 32.37
      • Published

      opencode-update-guard

      CLI tool that gates npm updates behind a configurable maturity cooldown

      • v0.5.0
      • 32.35
      • Published

      ringfence

      Sandbox npm/pnpm/yarn/bun install with bwrap (Linux) or Docker (macOS) to keep secrets in the working directory and host $HOME out of reach of postinstall scripts.

      • v0.2.6
      • 32.27
      • Published

      depguard-cli

      MCP security server for AI coding agents. Workspace auto-exec audit (pre-open repo scan, defends against fake-interview / take-home-test malware), static code analysis, behavioral detection, pre-install guardian, AI hallucination guard, dead dependency de

      • v1.14.0
      • 32.12
      • Published

      np-audit

      Static obfuscation detector for npm lifecycle scripts — supply chain attack prevention

      • v2.2.0
      • 32.11
      • Published

      kxco-verify

      Standalone, browser-safe verifier for KXCO ML-DSA-65 post-quantum signed attestations and credentials — for auditors, regulators, counterparties, and anyone who needs to confirm a signature without running the full KXCO SDK.

      • v1.0.5
      • 31.91
      • Published

      infynon

      Security-first CLI for AI-assisted development: safe package installs, dependency scanning, API flow testing, and agent task orchestration.

      • v0.2.12
      • 31.85
      • Published

      guardskills

      Security wrapper around skills add

      • v1.2.1
      • 31.84
      • Published

      expecto-security

      Supply-chain firewall for AI coding tools

        • v0.1.17
        • 31.64
        • Published

        @ar27111994/agent-harness

        Node.js TypeScript CLI for discovering, staging, activating, and wiring reusable AI-agent assets across supported developer hosts.

        • v1.0.8
        • 31.55
        • Published

        @shoulderdev/cli

        Shoulder — local-first trust scanner for developers and AI coding agents.

        • v0.0.2
        • 31.38
        • Published

        @vibecontrols/vibe-plugin-security

        Security lifecycle orchestrator — dispatches to per-stage security providers (secrets, sbom, release-gate, etc.).

        • v2026.601.3
        • 31.21
        • Published

        sigild

        Claude can sign, but never see. MCP server + CLI that keeps private keys out of the LLM's context window.

        • v0.0.8
        • 30.92
        • Published

        @balkanbrs/munack-core

        Core engine for detecting fake packages, fake imports, slopsquatting risk, and hallucinated dependencies in AI-generated code.

        • v0.1.12
        • 30.92
        • Published

        node-addon-slsa

        Provenance verification for prebuilt native addons with GitHub attestations

        • v1.0.0
        • 30.91
        • Published

        @peac/mappings-slsa

        SLSA v1.2 provenance mapping for PEAC provenance extension

        • v0.15.0
        • 30.83
        • Published

        @peac/mappings-intoto

        in-toto v1.0 attestation mapping for PEAC provenance extension

        • v0.15.0
        • 30.79
        • Published

        npm-scan-plus

        Security scanner for npm packages - pre and post-install scanning for malicious code, supply chain attacks, and obfuscated code

        • v1.1.1
        • 30.53
        • Published

        execfence

        Guard package-manager installs, dependency changes, CI, and agent-run commands before suspicious project code executes.

        • v5.0.2
        • 30.51
        • Published

        ossguard

        One CLI to guard any OSS project with OpenSSF security best practices — bootstrap, scan, and monitor.

        • v0.1.4
        • 30.46
        • Published

        packsentry

        npm dependency security scanner and package threat analysis tool

        • v2.1.1
        • 30.18
        • Published

        decoy-scan

        Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.

        • v0.8.0
        • 30.04
        • Published

        @openagentlock/cli

        OpenAgentLock CLI — a firewall for AI coding agents. Detects local agent harnesses (Claude Code, Codex CLI, Cursor, OpenCode, Cline, Gemini CLI, Continue, Copilot), gates risky tool calls via a Go control plane, anchors decisions in a Rust Merkle ledger.

        • v0.1.24
        • 29.86
        • Published

        sandcheck

        Check your npm packages against a curated list of known-compromised versions. Scans package-lock.json, pnpm-lock.yaml, and yarn.lock. Built for the AI-coding era.

        • v0.2.5
        • 29.84
        • Published

        trustdep

        npm supply chain security scanner — detect typosquatting, maintainer changes, and malicious scripts before npm install

        • v1.2.2
        • 29.73
        • Published

        @nexus_js/audit

        Nexus Dependency Auditor — OSV CVE scanning, offline cache, supply chain risk analysis, and build-time blocking

        • v0.9.30
        • 29.41
        • Published

        @sandcheck/mcp

        Model Context Protocol server that lets AI coding assistants (Claude Code, Cursor, Windsurf) check npm packages against the Sandcheck dataset before suggesting installs.

        • v0.3.4
        • 29.41
        • Published

        @cyberhub/trust-colors

        Security Trust Report: colors@1.4.0 — 46/100 (C, caution). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

        • v1.0.65
        • 29.17
        • Published

        kyos-cli

        Bootstrap and safely evolve a shared Claude Code repo structure.

        • v1.1.0
        • 29.13
        • Published

        exfil-poc

        PoC package in npm for data exfil

        • v3.0.0
        • 29.11
        • Published

        @ggui-ai/gadget-signing

        Gadget bundle signing + verification for the ggui gadget marketplace. Ed25519 author-key path + sigstore/cosign keyless path. Pure-TS @noble crypto for Ed25519 — browser-safe.

        • v0.1.0-rc.1
        • 29.10
        • Published

        @flupkejs/cli

        One command. Safer dependencies.

        • v1.3.0
        • 29.06
        • Published

        @sandcheck/core

        Core lookup library for Sandcheck. Loads the curated compromised-package dataset, validates it against the JSON Schema, and resolves package@version queries against it.

        • v0.2.4
        • 28.92
        • Published

        @arcane-spark/ubel-node

        Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.

        • v0.3.0
        • 28.84
        • Published

        supply-chain-inspector

        Standalone, zero-dependency CLI for npm supply chain security analysis — vulnerability scanning, OpenSSF Scorecard, install-script detection, publisher history, and more.

        • v1.10.0
        • 28.74
        • Published

        @lowwattlabs/frisk

        ⚡ Frisk — Catches leaked credentials and supply-chain threats in ClawHub skills before you install. 9 intel sources, 7 checks, zero phone-home.

        • v3.1.2
        • 28.70
        • Published

        vibecheck-ai

        VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

        • v6.0.5
        • 28.36
        • Published

        @gtcx/sdk

        Official TypeScript SDK for GTCX Protocol

        • v0.4.0
        • 28.06
        • Published

        amifcked

        Find installed binaries and packages tied to supply-chain attacks or AI security incidents.

        • v0.1.5
        • 27.97
        • Published

        @vouchjs/vouch

        A dependency-decision ledger: every dependency is recorded, explained, and reviewable in the PR — for Node.js projects and coding agents.

        • v0.4.0
        • 27.90
        • Published

        @vibecontrols/vibe-plugin-security-package-publish

        Cosign signing + SLSA provenance for the package.publish lifecycle stage. Signs the published artifact (keyless via Fulcio OIDC when available, or with input.config.cosignKey for key-based) and emits an intoto+json SLSA provenance document. Registers as a

        • v2026.528.5
        • 27.83
        • Published

        @cyberhub/trust-sprintsail-cli

        Security Trust Report: @sprintsail/cli@0.2.1 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

        • v1.0.3
        • 27.83
        • Published

        d1337-kit

        D1337 CIPHER-OSC V3 — Elite AI Agent Framework. 106+ components. Hooks, subagents, custom commands. Underground mindset, brutal execution, sovereign protocol.

        • v5.0.0
        • 27.81
        • Published

        @cyberhub/trust-event-stream

        Security Trust Report: event-stream@4.0.1 — 53/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

        • v1.0.64
        • 27.69
        • Published

        npmdstesto2

        A proof-of-concept demonstrating how npm packages can execute code during installation

          • v1.0.2
          • 27.66
          • Published

          @safedep/cli

          SafeDep CLI: open source software supply chain security

          • v0.1.5
          • 27.54
          • Published

          pkgradar

          Content-based supply-chain scanner for npm/pnpm/yarn/bun: inspects the bytes you actually installed (lifecycle hooks, obfuscated payloads, worm IOCs) instead of just matching package names against an advisory list.

          • v0.1.4
          • 27.52
          • Published

          @attestd/mcp

          MCP server exposing Attestd CVE and supply-chain checks for Claude Code and other MCP clients

          • v0.1.2
          • 27.49
          • Published

          @cyberhub/trust-rc

          Security Trust Report: rc@1.2.8 — 56/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

          • v1.0.64
          • 27.43
          • Published

          depsentinel

          JS/TS supply-chain hardening CLI — scan, secure, and enforce dependency policies

          • v0.2.0
          • 27.37
          • Published

          hs-code-classifier-mcp

          HS code classifier for AI agents. Classifies products to official 6-digit tariff codes before customs declarations or duty calculations. VERIFIED verdict in one call.

          • v1.0.13
          • 27.36
          • Published

          @froggychips/mcp-vault

          Deterministic registry + integrity scanner for Model Context Protocol servers. Make MCP supply-chain boring.

          • v0.10.0
          • 27.24
          • Published

          @tdspt/dep3nds-lvl1

          [THIS IS A TEST] Level-1 dependency used to introduce a transitive sub-dependency for SBOM/visibility validation.

            • v4.3.3
            • 27.17
            • Published

            patient-zero

            Scans Node, Python, and AI-agent configs for indicators of compromise from npm and PyPI supply-chain attacks.

            • v0.2.1
            • 27.12
            • Published

            @kimuson/npm-fw

            npm registry proxy firewall — blocks vulnerable packages before they reach node_modules

            • v0.0.4
            • 27.08
            • Published

            wormguard

            Offline AST-grade npm/pnpm/yarn/bun supply-chain auditor that flags Shai-Hulud-style install-script worms. Real JavaScript AST analysis with taint approximation, IoC corpus matching, sigstore provenance verification, and baseline diffing — designed as def

            • v1.0.3
            • 26.99
            • Published

            marinate-cli

            npm outdated, but only for packages that have had time to age safely

            • v0.4.0
            • 26.99
            • Published

            clawvet

            Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.

            • v0.7.1
            • 26.99
            • Published

            @moriito/sentinel-ai

            CLI tool to detect AI hallucinated packages and npm vulnerabilities

            • v0.2.1
            • 26.96
            • Published

            @cyberhub/trust-faker

            Security Trust Report: faker@6.6.6 — 54/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

            • v1.0.65
            • 26.96
            • Published

            @epilot/lockfile-checker

            CLI that fails if any package version in (or newly added to) a lockfile is younger than a configurable threshold on the npm registry. Defends against supply-chain attacks via a quarantine window.

            • v1.1.0
            • 26.80
            • Published

            gerardian

            Robust, framework-agnostic security middleware and monitoring SDK for distributed retail and supply chain applications

            • v1.0.7-stable
            • 26.76
            • Published

            npcooldown

            Protect yourself from npm supply chain attacks. One command sets up minimumReleaseAge cooldowns across npm, pnpm, Yarn, and Bun globally.

            • v1.0.0
            • 26.75
            • Published

            @attestd/sdk

            Official JavaScript/TypeScript client for the Attestd security risk API

            • v0.1.2
            • 26.74
            • Published

            quaid-scanner

            Agent-first OSS repository health scanner based on CHAOSS metrics, The Open Source Way 2.0, and Inclusive Naming Initiative

            • v0.1.3
            • 26.69
            • Published

            patchpilot-cli

            Standalone supply-chain scanner (npm + PyPI) with reachability (VEX-lite) triage, powered by OSV. Part of PatchPilot.

            • v0.1.3
            • 26.64
            • Published

            @cyberhub/trust-jst

            Security Trust Report: jst@0.0.13 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

            • v1.0.5
            • 26.55
            • Published

            @cyberhub/trust-flatmap-stream

            Security Trust Report: flatmap-stream@0.0.1-security — 50/100 (C, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

            • v1.0.61
            • 26.53
            • Published

            @happyberg/pkg-quarantine

            Unified quarantine policy for package managers — block recently-published packages to prevent supply-chain attacks

            • v0.2.4
            • 26.28
            • Published

            github-security-mcp

            GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

            • v0.1.0
            • 26.28
            • Published

            worm-sign

            A security scanner that detects npm packages compromised by supply chain attacks, including the TanStack wave 4 attack (May 2026), the Axios attack (March 2026), and Shai-Hulud malware.

            • v4.2.0
            • 26.09
            • Published

            @cyberhub/trust-wepback

            Security Trust Report: wepback@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

            • v1.0.5
            • 26.06
            • Published

            bumblebee-scan

            Supply-chain inventory collector for package, extension, and developer-tool metadata on macOS and Linux.

            • v0.1.5
            • 26.01
            • Published

            agent-cognicheck

            Local-first security and cognitive-risk scanner for MCP tools and agent skills with ToolBOM, attack harness, and policy checks.

            • v0.2.0
            • 25.98
            • Published

            npm-security-guardian

            A TypeScript CLI and VSCode extension that scans npm dependencies for security and supply-chain risk.

            • v1.1.0
            • 25.97
            • Published

            @jbendz/scg-cli

            Supply Chain Guard CLI - Secure front door for npm: per-session install guard, mandatory preflight, phantom detection, governance checks

              • v0.8.3
              • 25.90
              • Published

              @namaa03/pushguard

              One-time install git push protection with 1000+ provider fingerprints and entropy scanning for leaked tokens.

                • v0.6.4
                • 25.88
                • Published

                ossrisk

                Scan dependencies for supply-chain risk: EOL versions, CVEs, abandonment, typosquatting, license compliance, and maintainer takeover patterns

                • v0.5.5
                • 25.85
                • Published

                @stackbilt/policies

                Supply chain policy stamping — detect, patch, and generate CI workflows for org-wide policy adoption

                • v1.0.0
                • 25.81
                • Published

                plugin-hunter

                ph — Scan Claude Code / Codex CLI / Gemini CLI plugins for malicious hooks, poisoned SKILL.md, and MCP tool-poisoning *before* you install. Uses your local LLM CLI as the judge — no API key required.

                • v1.1.1
                • 25.80
                • Published

                suspicious-package

                Intentionally suspicious npm package for evaluating supply-chain security scanners.

                  • v0.1.0
                  • 25.79
                  • Published

                  mini-shai-hulud-scanner

                  Tiny zero-dependency CLI that scans npm, pnpm, yarn, and bun lockfiles for packages compromised in the TanStack May 2026 npm supply-chain incident (mini Shai-Hulud). Uses the official Snyk advisory as the source of truth.

                    • v1.3.0
                    • 25.77
                    • Published

                    @emstack/tanstack-supply-chain-checker

                    Detect and fix the mini-shai-hulud TanStack supply-chain attack (socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack)

                    • v1.2.0
                    • 25.58
                    • Published

                    autoremediator

                    Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.

                    • v0.15.0
                    • 25.41
                    • Published

                    @fendsh/cli

                    Fend off risky dependencies. Sandboxed runtime for package installs and dev scripts.

                    • v0.1.0-alpha.2
                    • 25.37
                    • Published

                    @arcis/cli

                    Arcis security CLI — scan running apps, audit source, and check dependencies. Native Rust binary distributed via npm.

                    • v1.2.0
                    • 25.35
                    • Published

                    @404labs/securitycheck

                    Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.

                    • v0.2.1
                    • 25.27
                    • Published

                    @cyberhub/trust-loadash

                    Security Trust Report: loadash@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                    • v1.0.3
                    • 25.26
                    • Published

                    @cyberhub/trust-nesk-scanner-termux

                    Security Trust Report: nesk-scanner-termux@8.0.6 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                    • v1.0.4
                    • 25.24
                    • Published

                    @peachstudio/synapse-sbom

                    SYNAPSE SBOM scanner for npm projects — generate a CycloneDX SBOM locally and submit it to SYNAPSE Software Component Analysis.

                    • v0.1.1
                    • 25.11
                    • Published

                    @kevinpatil/devguard

                    CLI tool that audits env files, dependencies, and React code quality before your app ships

                    • v3.4.0
                    • 25.04
                    • Published

                    @cyberhub/trust-cairncms-api

                    Security Trust Report: @cairncms/api@1.0.0 — 58/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                    • v1.0.3
                    • 25.01
                    • Published

                    @aissabelkoussa/cupel

                    Cupel — audit local des skills IA (Claude Code, Cursor, Codex). 14 règles de détection : prompt injection, ASCII smuggling, tool poisoning, exfiltration credentials, reverse shells, obfuscation hex. Zero network. Inspiré de la coupelle de l'essayeur d'or,

                    • v0.3.3
                    • 24.95
                    • Published

                    @weave_protocol/tollere

                    Supply chain security for AI-generated code - scans packages, Docker images, and IDE extensions (VS Code, Cursor, JetBrains) before install for typosquats, CVEs, sandwich-pattern attacks, and Docker tag overwriting

                    • v0.2.3
                    • 24.94
                    • Published

                    @cyberhub/trust-n3xt

                    Security Trust Report: n3xt@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                    • v1.0.5
                    • 24.85
                    • Published

                    @metrc/retailid

                    Official SDK for encoding and decoding Metrc RetailID QR labels

                    • v0.10.1
                    • 24.84
                    • Published

                    caplabel

                    Offline, zero-dependency static capability analyzer for JavaScript — see what a script can do (network, filesystem, exec, secrets) before you run it.

                    • v0.1.2
                    • 24.84
                    • Published

                    protaction

                    A terminal-first supply chain guard for package manager workflows.

                    • v0.1.1
                    • 24.72
                    • Published

                    easy-dep-graph

                    Easily see the dependency graph of your npm project

                    • v1.2.2
                    • 24.63
                    • Published

                    @devshub198211/devguard

                    14-module security, AI, auth & DX toolkit for Node.js. Zero dependencies.

                    • v2.0.3
                    • 24.57
                    • Published

                    defarm-sdk

                    DeFarm SDK - Git for traceability with multi-role permissions and global item discovery for agriculture supply chain

                      • v3.0.3
                      • 24.57
                      • Published

                      @cyberhub/trust-openclaw

                      Security Trust Report: openclaw@2026.5.18 — 57/100 (C+, standard). 22 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                      • v1.0.4
                      • 24.56
                      • Published

                      @crbroughton/recul

                      Stay N versions behind the latest published release of your npm dependencies to avoid supply chain attacks.

                      • v0.6.2
                      • 24.56
                      • Published

                      @opencodereview/core

                      Core detection engine for AI-generated code — hallucinated packages, phantom dependencies, stale APIs, security anti-patterns. Structural, embedding, and LLM scanning.

                      • v2.1.3
                      • 24.55
                      • Published

                      @cyberhub/trust-resin-stream-logger

                      Security Trust Report: resin-stream-logger@0.1.2 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                      • v1.0.2
                      • 24.53
                      • Published

                      depscope-mcp

                      Package Intelligence MCP server for AI agents. Stops hallucinated/malicious package installs across 19 ecosystems (npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia). 22 to

                      • v0.9.0
                      • 24.51
                      • Published

                      @classytic/flow

                      Production-grade inventory kernel and supply chain engine for MongoDB — locations, moves, quants, reservations, valuation, routing, traceability

                      • v0.2.6
                      • 24.47
                      • Published

                      slopcheck

                      Scan markdown and config files for hallucinated npm package names. Defends against slopsquatting supply chain attacks.

                      • v0.2.0
                      • 24.46
                      • Published

                      safedeps

                      Open source npm package security scanner — catch supply chain attacks before they catch you.

                        • v1.2.1
                        • 24.44
                        • Published

                        mcp-secure

                        MCPS -- MCP Secure. Drop-in secure replacement for the MCP SDK. ECDSA message signing, body integrity, replay protection, tool integrity, and audit trail.

                        • v2.0.1
                        • 24.40
                        • Published

                        bheeshma

                        Runtime dependency behavior monitor for Node.js — the strace for npm packages. Detects supply-chain attacks that static analysis misses. Zero dependencies. Zero config. Zero telemetry.

                        • v3.0.0
                        • 24.32
                        • Published

                        cowcare-sdk

                        JavaScript/TypeScript SDK for the CowCare MilkSupplyChain contract on Celo

                        • v1.0.2
                        • 24.30
                        • Published

                        trawly

                        Dependency risk gate for JavaScript projects: OSV advisories, SBOM scans, baselines, install blocking, and supply-chain risk signals.

                          • v0.1.1
                          • 24.29
                          • Published

                          sec-gate

                          Pre-commit security gate for OWASP Top 10 2021 — SAST, SCA and misconfig checks for Node/Express, Go and React codebases

                          • v0.2.1
                          • 24.21
                          • Published

                          guard-install

                          Stop installing npm packages blindly. Pre-install security scanner for npm packages and GitHub repos.

                          • v1.0.1
                          • 24.20
                          • Published

                          supplychain-sentry

                          Scan npm dependencies for supply chain security risks - detect malicious packages before they compromise your project

                          • v1.0.1
                          • 24.17
                          • Published

                          security-mcp

                          AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

                          • v1.1.4
                          • 24.12
                          • Published

                          npm-verify-guard

                          Global npm vulnerability and malware verifier with install-time blocking

                          • v1.0.1
                          • 24.08
                          • Published

                          @opencodereview/cli

                          Detect AI-hallucinated packages, phantom dependencies, and stale APIs in your codebase. Open-source CI/CD quality gate with local Ollama support — zero API cost.

                          • v2.1.5
                          • 24.03
                          • Published

                          @cyberhub/trust-scopieflows-pieces-common

                          Security Trust Report: @scopieflows/pieces-common@0.11.2 — 56/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.2
                          • 23.99
                          • Published

                          hound-mcp

                          The dependency bloodhound for AI coding agents. Sniffs out vulnerabilities, license risks, and health issues in your dependencies — free, no API keys.

                          • v0.2.4
                          • 23.99
                          • Published

                          n8n-nodes-tracepass

                          n8n community node for TracePass — automate EU Digital Product Passport workflows: products, passports, EPCIS supply-chain events.

                          • v1.0.6
                          • 23.97
                          • Published

                          @aldegad/safedeps

                          Dependency install safety gate with OSV-backed advisory checks, approved-spec ledger enforcement, and reorg rollback hooks

                          • v2.6.1
                          • 23.95
                          • Published

                          age-install

                          Delay npm package installations until they reach a minimum age, protecting against supply chain attacks

                          • v0.1.1
                          • 23.94
                          • Published

                          web-secure-verification

                          Security scanning CLI for React and Next.js — detects CVEs, secrets, license risks, supply chain threats, hydration bugs, RSC boundary violations, and more.

                            • v1.0.1
                            • 23.84
                            • Published

                            colour-shield

                            Post-quantum cryptographic security layer for npm, pip, and cargo package managers

                            • v0.1.1
                            • 23.77
                            • Published

                            @ediflow/edifact-d20b

                            EDIFACT D.20B (2020) Standard Definitions - Latest Standard - 195 Message Types

                            • v0.3.1
                            • 23.74
                            • Published

                            pnpm-shield

                            Supply chain attack protection audit tool for pnpm projects

                            • v1.0.1
                            • 23.69
                            • Published

                            @elliotllliu/agent-shield

                            Multi-engine AI agent security scanner — one scan, four engines, one report

                            • v0.16.0
                            • 23.63
                            • Published

                            @umarise/cli

                            Anchor files to Bitcoin from the command line. Generate .proof bundles for offline verification.

                            • v1.4.0
                            • 23.49
                            • Published

                            create-supplynet-app

                            Scaffold a full-stack SupplyNet SCMS project in one command

                              • v1.0.1
                              • 23.47
                              • Published

                              @cyberhub/trust-scopieflows-app-gistly

                              Security Trust Report: @scopieflows/app-gistly@0.1.3 — 72/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.2
                              • 23.47
                              • Published

                              @cyberhub/trust-qihuangai-api

                              Security Trust Report: @qihuangai/api@1.0.0-beta.4 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.2
                              • 23.41
                              • Published

                              @moshyfawn/safeship

                              One-shot setup for secure npm package publishing: OIDC trusted publishing, staged publishing, hardened CI/CD.

                              • v0.0.1
                              • 23.39
                              • Published

                              tops-bmad

                              CLI tool to install BMAD workflow files into any project with integrated Shai-Hulud 2.0 security scanning

                                • v1.2.59
                                • 23.31
                                • Published

                                verimu

                                CRA compliance automation - SBOM generation, CVE monitoring, and vulnerability reporting for the EU Cyber Resilience Act.

                                • v0.0.22
                                • 23.27
                                • Published

                                @digi4care/shai-scan

                                Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).

                                • v0.1.1
                                • 23.19
                                • Published

                                llm-trust-guard

                                Comprehensive security guards for LLM-powered and agentic AI applications - 34 guards covering OWASP Top 10 for LLMs 2025, Agentic Applications 2026, and MCP Security. All guards accessible via unified TrustGuard facade. Features prompt injection (PAP/per

                                • v4.20.1
                                • 23.15
                                • Published

                                agentlint

                                Static analysis and security scanner for AI agent configuration files

                                • v0.3.0
                                • 23.11
                                • Published

                                @pkg-guard/mcp

                                Open-source MCP server that flags day-zero supply-chain anomalies in npm + PyPI packages before install.

                                • v1.0.1
                                • 23.11
                                • Published

                                agent-skillguard

                                Policy-as-code admission controller for AI agent skills and MCP tools with SkillBOM, lockfiles, and supply-chain baselines.

                                • v1.1.0
                                • 23.00
                                • Published

                                shai-hulud-inspector

                                Security scanner that checks npm dependencies for Shai Hulud vulnerable packages. 100% offline, zero data collection, zero telemetry. Scans all dependencies against 689+ known compromised packages.

                                • v1.0.6
                                • 22.96
                                • Published

                                @ikotas-labs/satoki

                                Security namespace placeholder for satoki. Registered to prevent supply chain attacks.

                                • v1.0.0
                                • 22.92
                                • Published

                                chainsentry

                                Supply-chain scanner that audits npm dependencies for typosquats, malicious install scripts, license risk, and known CVEs.

                                • v0.2.0
                                • 22.91
                                • Published

                                safeinstall-cli

                                Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.

                                • v0.5.0
                                • 22.90
                                • Published

                                actions-warden

                                Audit, pin, and upgrade GitHub Actions workflows. LLM-friendly TOON output, safe-by-default.

                                • v0.1.1
                                • 22.84
                                • Published

                                @cra-ready/cli

                                Push SBOMs to CRA Ready from your terminal or CI.

                                • v0.1.1
                                • 22.72
                                • Published

                                aicopycheck

                                Scan your codebase for AI-generated code. Know your copyright risk before it becomes a legal problem.

                                • v1.0.1
                                • 22.72
                                • Published

                                formulab

                                Manufacturing & Engineering calculation formulas library - 182 industrial calculations across 15 domains for OEE, Cpk, SPC, FMEA, Nelson Rules, metal weight, CNC machining, GD&T, battery, environmental, pipe flow, logistics, IE time study, and more

                                • v0.12.1
                                • 22.71
                                • Published

                                superkit-cliii

                                Scaffold full-stack MERN exam projects - SMS, SRMS, SCMS, EPMS. Select, install, and run in seconds.

                                • v1.0.1
                                • 22.68
                                • Published

                                @agentlair/spa-verifier

                                Verify Skill Provenance Attestations (SPA) for AI agent skill directories. Drop-in tamper-evidence for any registry, runner, or installer. Zero-deps, Web Crypto, Ed25519/JWS.

                                • v0.2.0
                                • 22.65
                                • Published

                                @cyberhub/trust-word-wrap

                                Security Trust Report: word-wrap@1.2.5 — 65/100 (B, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                                • v1.0.10
                                • 22.57
                                • Published

                                @vibecheckai/cli

                                Vibecheck CLI - Ship with confidence. One verdict: SHIP | WARN | BLOCK.

                                • v4.0.2
                                • 22.55
                                • Published

                                @sathyendra/security-checker

                                Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s

                                • v1.26.0
                                • 22.55
                                • Published

                                @cyberhub/trust-scopieflows-shared

                                Security Trust Report: @scopieflows/shared@0.54.0 — 54/100 (C, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                • v1.0.2
                                • 22.41
                                • Published

                                depgraph-scanner

                                Dependency health scores and abandonment risk forecasting for npm projects

                                • v1.0.1
                                • 22.35
                                • Published

                                license-check-cli

                                Scan npm project dependencies and flag copyleft/restrictive licenses (GPL, AGPL, LGPL, SSPL). Zero dependencies — pure Node.js built-ins.

                                • v1.0.1
                                • 22.16
                                • Published

                                @ediflow/eancom-2002

                                EANCOM 2002 (S3) Standard Definitions - 49 Message Types for Retail & Supply Chain

                                • v0.3.1
                                • 22.16
                                • Published

                                @libguard/cli

                                Shield your projects from npm supply-chain attacks. Checks packages against a curated registry of malicious, compromised, and typosquatted packages before installation.

                                • v0.1.1
                                • 22.06
                                • Published

                                pi-sandbox-proxy

                                pi coding-agent extension that intercepts network operations with approval flows, vulnerability scanning, and supply chain security enforcement.

                                • v0.1.5
                                • 21.96
                                • Published

                                @cyberhub/trust-coa

                                Security Trust Report: coa@2.0.2 — 64/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                                • v1.0.12
                                • 21.96
                                • Published

                                @cyberhub/trust-commondir

                                Security Trust Report: commondir@1.0.1 — 65/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                • v1.0.10
                                • 21.91
                                • Published

                                @cyberhub/trust-node-ipc

                                Security Trust Report: node-ipc@12.0.0 — 68/100 (B, standard). 3 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                • v1.0.11
                                • 21.86
                                • Published

                                @yangyixxxx/skill-guard

                                Local-first security scanner for AI Skills (Anthropic Skill bundles, Niuma, OpenClaw, MCP, GPTs Actions). Catches malicious code, supply-chain attacks, and prompt injection — pure static analysis, sub-2s, zero LLM cost.

                                • v0.1.0
                                • 21.74
                                • Published

                                @agentpost/mcp-server

                                MCP server exposing all 9 AgentPost data verticals as AI agent tools

                                  • v1.0.0
                                  • 21.55
                                  • Published

                                  sentinel-check

                                  Security gate for npm, yarn and pnpm: verifies lockfile integrity and tarball hashes before installation

                                  • v2.1.2
                                  • 21.47
                                  • Published

                                  @supplyflow/mcp

                                  MCP client adapter for connecting AI agents to Supplyflow Hospital Supply Chain Management API

                                  • v0.1.3
                                  • 21.41
                                  • Published

                                  @ajna-inc/npmvc

                                  Verifiable-credential supply chain compliance for npm. Sign attestations, verify dependencies, revoke compromised packages.

                                  • v0.3.4
                                  • 21.41
                                  • Published

                                  @hikae/pmsec

                                  Inspect and apply install-time cooldown (min-release-age / exclude-newer) for npm and uv.

                                  • v0.2.4
                                  • 21.33
                                  • Published

                                  @agentvet/cli

                                  Security scanner for AI agent skills, configs, and MCP tools. Vet before you trust.

                                  • v0.17.6
                                  • 21.21
                                  • Published

                                  ironward

                                  Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,

                                  • v3.2.0
                                  • 21.20
                                  • Published

                                  @ediflow/edifact

                                  EDIFACT EDI Parser - Format-specific infrastructure for UN/EDIFACT standard

                                  • v0.3.0
                                  • 21.10
                                  • Published

                                  @v0idd0/depcheck

                                  depcheck — dependency scanner. 47-entry offline CVE database (incl. 2024 and supply-chain), unused/missing deps via static import analysis, transitive deps via package-lock.json, Python support (requirements.txt / pyproject.toml). Free forever from vøiddo

                                  • v2.0.3
                                  • 21.05
                                  • Published

                                  fast-graph

                                  A fast implementation of graph data structure

                                  • v1.5.0
                                  • 21.03
                                  • Published

                                  git-tag-guardian

                                  Zero-dependency supply chain defense for Node.js/Bun — detects git tag rewrite attacks, postinstall backdoors, SHA drift, tarball tampering and unpinned GitHub Actions

                                  • v1.0.0
                                  • 20.94
                                  • Published

                                  bumblebee-scanner

                                  A cross-platform wrapper for Perplexity's Bumblebee supply-chain inventory scanner.

                                  • v1.0.0
                                  • 20.90
                                  • Published

                                  nono-eti-lifecycle-demo

                                  Harmless npm lifecycle package for demonstrating nono ETI command mediation.

                                    • v0.1.0
                                    • 20.90
                                    • Published

                                    @geenius/release-toolkit

                                    Centralized, opt-out-able release toolkit for every Geenius package and boilerplate. One canonical CLI (geenius-release) replaces the per-package supply-chain / license / SBOM / smoke-packed / gauntlet scripts.

                                    • v0.10.0
                                    • 20.84
                                    • Published

                                    depgrave

                                    Analyzes your full dependency tree — last commit date, open CVEs, bus factor, and risk score per package

                                    • v1.0.0
                                    • 20.79
                                    • Published

                                    guardrail-cli

                                    Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                                    • v2.5.4
                                    • 20.64
                                    • Published

                                    npm-package-doctor

                                    Analyze npm dependencies and generate package health, security, and maintainability reports.

                                    • v0.1.0
                                    • 20.58
                                    • Published

                                    depsignal

                                    Dependency health intelligence CLI — catch risks before they become crises

                                    • v1.0.0
                                    • 20.57
                                    • Published

                                    @araptus/npm-security-scanner

                                    A fast, configurable CLI tool that scans your dependencies against a continuously-updated database of known compromised npm packages. Supports deep scanning of transitive dependencies via lock files.

                                    • v2.0.2
                                    • 20.47
                                    • Published

                                    @cyberhub/trust-boxes-dev-dvb

                                    Security Trust Report: @boxes-dev/dvb@1.0.655 — 61/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                    • v1.0.11
                                    • 20.46
                                    • Published

                                    depstop

                                    Zero-config CLI security gate — blocks risky dependency installs before they reach production

                                    • v0.1.0
                                    • 20.36
                                    • Published

                                    dryinstall

                                    npm supply chain attack defense via execution isolation

                                    • v0.8.0
                                    • 20.35
                                    • Published

                                    scanrepo

                                    Scan any GitHub or Bitbucket repo for malware, credential stealers, and crypto scams

                                    • v0.1.0
                                    • 20.28
                                    • Published

                                    ext-scan

                                    Local scanner for installed VS Code and Cursor extensions — catalog matching, static analysis, optional AI deep scan

                                      • v0.1.0
                                      • 20.14
                                      • Published

                                      ngx-security-audit

                                      The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

                                      • v2.0.1
                                      • 20.05
                                      • Published

                                      skilllock

                                      Reproducible lockfiles, verification, diff, audit, and tests for Agent Skills

                                      • v1.1.0
                                      • 20.04
                                      • Published

                                      @agentsec/cli

                                      AI-powered security scanner with 15 scan phases, 10 specialist agents, container/IaC/DAST/taint analysis, and AI-assisted remediation.

                                      • v0.1.6
                                      • 20.02
                                      • Published

                                      npmguard-cli

                                      NpmGuard CLI — check npm packages against NpmGuard security audits

                                        • v1.1.1
                                        • 19.96
                                        • Published

                                        @besile/scm-cli

                                        SCM CLI - Supply Chain Management CLI tool

                                        • v2026.4.21
                                        • 19.95
                                        • Published

                                        @cyberhub/trust-axios

                                        Security Trust Report: axios@1.14.0 — 65/100 (B, standard). 8 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                        • v1.0.9
                                        • 19.83
                                        • Published

                                        @cyberhub/trust-opencode-ai

                                        Security Trust Report: opencode-ai@1.14.30 — 62/100 (C+, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                        • v1.0.8
                                        • 19.64
                                        • Published

                                        dep-oracle

                                        Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis for your supply chain.

                                        • v1.4.0
                                        • 19.52
                                        • Published

                                        verdaccio-age-gate

                                        Verdaccio middleware that blocks npm packages published less than N days ago, reducing supply-chain attack risk.

                                        • v1.0.0
                                        • 19.51
                                        • Published

                                        shai-hulud-scan

                                        A CLI tool for detecting the 'Shai-Hulud' npm supply chain attack that occurred in September 2025

                                        • v1.1.2
                                        • 19.45
                                        • Published

                                        pnpm-audit-hook

                                        pnpm hook that blocks vulnerable packages before download. Uses GitHub Advisory Database with offline static DB fallback.

                                        • v1.4.3
                                        • 19.43
                                        • Published

                                        @dendronhq/safe-npm

                                        A security-focused npm installer that protects your projects from newly compromised packages

                                          • v0.1.0
                                          • 19.36
                                          • Published

                                          vigiskill

                                          Vigiskill — security workbench for AI agent skills and OpenClaw mirror integrity. This is a placeholder package reserving the name for the upcoming production release.

                                          • v0.0.1
                                          • 19.34
                                          • Published

                                          @skillgate/openclaw-skillgate

                                          Supply-chain governance plugin for OpenClaw - scan, assess, and quarantine risky skills

                                          • v0.1.3
                                          • 19.31
                                          • Published

                                          @leochong/npm-scan

                                          Powerful npm supply chain security scanner - detects malicious packages (Shai-Hulud style), behavioral analysis, SBOM, and compliance reporting.

                                          • v0.1.0
                                          • 19.17
                                          • Published