JSPM

Found 1210 results for supply-chain

leedab

A local AI operating system that learns your operations and runs them with Artificial Beings. Across portals, ERPs, dashboards, inboxes, spreadsheets, and PDFs. On your hardware. Your data. No APIs.

    • v0.9.1
    • 34.25
    • Published

    @kratex/cli

    Node.js supply-chain enforcement at install and at runtime. Policy-gated lifecycle scripts, caller-chain-attributed runtime hook.

    • v0.5.0
    • 34.13
    • Published

    pmsec

    Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, uv, and bundler.

    • v0.13.0
    • 34.12
    • Published

    @kratex/shared

    Policy schema, resolved-rule types, normalizer, and route contracts shared across Kratex components.

    • v0.5.0
    • 33.05
    • Published

    @kosli/cli

    CLI client for reporting compliance events to https://kosli.com

    • v2.25.0
    • 32.94
    • Published

    @vionsec/cli

    VION Security CLI — secure-by-default installer for the VION agent across Claude Code, Blackbox AI, OpenAI Codex, and terminal.

    • v0.6.7
    • 32.81
    • Published

    aminet

    CLI and GitHub Action for npm supply chain security reviews

    • v0.4.0
    • 32.60
    • Published

    tip-verify

    CLI for verifying repository integrity roots against the TIP registry.

    • v0.2.6
    • 32.55
    • Published

    fad-checker

    Scan ALL Maven, npm, Yarn, Composer, Python, C#/.NET, Go & Ruby dependencies — plus embedded JARs (fat-jars/war/ear) — in a source tree ONE SHOT without mvn/python/etc — CVE (EPSS/KEV-prioritised), EOL, obsolete, outdated & licenses, with SBOM/CSAF/SARIF/

    • v2.2.4
    • 32.38
    • Published

    ship-safe

    AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a

    • v9.3.2
    • 32.38
    • Published

    depguard-cli

    MCP security server for AI coding agents. Workspace auto-exec audit (pre-open repo scan, defends against fake-interview / take-home-test malware), static code analysis, behavioral detection, pre-install guardian, AI hallucination guard, dead dependency de

    • v1.14.0
    • 32.31
    • Published

    ringfence

    Sandbox npm/pnpm/yarn/bun install with bwrap (Linux) or Docker (macOS) to keep secrets in the working directory and host $HOME out of reach of postinstall scripts.

    • v0.2.6
    • 32.28
    • Published

    opencode-update-guard

    CLI tool that gates npm updates behind a configurable maturity cooldown

    • v0.5.0
    • 32.26
    • Published

    np-audit

    Static obfuscation detector for npm lifecycle scripts — supply chain attack prevention

    • v2.2.0
    • 32.07
    • Published

    guardskills

    Security wrapper around skills add

    • v1.2.1
    • 32.02
    • Published

    kxco-verify

    Standalone, browser-safe verifier for KXCO ML-DSA-65 post-quantum signed attestations and credentials — for auditors, regulators, counterparties, and anyone who needs to confirm a signature without running the full KXCO SDK.

    • v1.0.5
    • 31.79
    • Published

    expecto-security

    Supply-chain firewall for AI coding tools

      • v0.1.17
      • 31.66
      • Published

      @ar27111994/agent-harness

      Node.js TypeScript CLI for discovering, staging, activating, and wiring reusable AI-agent assets across supported developer hosts.

      • v1.0.8
      • 31.51
      • Published

      @shoulderdev/cli

      Shoulder — local-first trust scanner for developers and AI coding agents.

      • v0.0.2
      • 31.39
      • Published

      @vibecontrols/vibe-plugin-security

      Security lifecycle orchestrator — dispatches to per-stage security providers (secrets, sbom, release-gate, etc.).

      • v2026.601.3
      • 31.04
      • Published

      @balkanbrs/munack-core

      Core engine for detecting fake packages, fake imports, slopsquatting risk, and hallucinated dependencies in AI-generated code.

      • v0.1.12
      • 30.93
      • Published

      sigild

      Claude can sign, but never see. MCP server + CLI that keeps private keys out of the LLM's context window.

      • v0.0.8
      • 30.80
      • Published

      @peac/mappings-slsa

      SLSA v1.2 provenance mapping for PEAC provenance extension

      • v0.15.0
      • 30.79
      • Published

      node-addon-slsa

      Provenance verification for prebuilt native addons with GitHub attestations

      • v1.0.0
      • 30.78
      • Published

      @peac/mappings-intoto

      in-toto v1.0 attestation mapping for PEAC provenance extension

      • v0.15.0
      • 30.75
      • Published

      execfence

      Guard package-manager installs, dependency changes, CI, and agent-run commands before suspicious project code executes.

      • v5.0.2
      • 30.69
      • Published

      npm-scan-plus

      Security scanner for npm packages - pre and post-install scanning for malicious code, supply chain attacks, and obfuscated code

      • v1.1.1
      • 30.54
      • Published

      infynon

      Security-first CLI for AI-assisted development: safe package installs, dependency scanning, API flow testing, and agent task orchestration.

      • v0.2.12
      • 30.52
      • Published

      ossguard

      One CLI to guard any OSS project with OpenSSF security best practices — bootstrap, scan, and monitor.

      • v0.1.4
      • 30.47
      • Published

      decoy-scan

      Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.

      • v0.8.0
      • 30.06
      • Published

      packsentry

      npm dependency security scanner and package threat analysis tool

      • v2.1.1
      • 29.98
      • Published

      trustdep

      npm supply chain security scanner — detect typosquatting, maintainer changes, and malicious scripts before npm install

      • v1.2.2
      • 29.75
      • Published

      sandcheck

      Check your npm packages against a curated list of known-compromised versions. Scans package-lock.json, pnpm-lock.yaml, and yarn.lock. Built for the AI-coding era.

      • v0.2.5
      • 29.72
      • Published

      @openagentlock/cli

      OpenAgentLock CLI — a firewall for AI coding agents. Detects local agent harnesses (Claude Code, Codex CLI, Cursor, OpenCode, Cline, Gemini CLI, Continue, Copilot), gates risky tool calls via a Go control plane, anchors decisions in a Rust Merkle ledger.

      • v0.1.24
      • 29.67
      • Published

      @nexus_js/audit

      Nexus Dependency Auditor — OSV CVE scanning, offline cache, supply chain risk analysis, and build-time blocking

      • v0.9.30
      • 29.42
      • Published

      @cyberhub/trust-colors

      Security Trust Report: colors@1.4.0 — 46/100 (C, caution). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.65
      • 29.34
      • Published

      @sandcheck/mcp

      Model Context Protocol server that lets AI coding assistants (Claude Code, Cursor, Windsurf) check npm packages against the Sandcheck dataset before suggesting installs.

      • v0.3.4
      • 29.22
      • Published

      @flupkejs/cli

      One command. Safer dependencies.

      • v1.3.0
      • 29.07
      • Published

      kyos-cli

      Bootstrap and safely evolve a shared Claude Code repo structure.

      • v1.1.0
      • 29.02
      • Published

      exfil-poc

      PoC package in npm for data exfil

      • v3.0.0
      • 29.00
      • Published

      @ggui-ai/gadget-signing

      Gadget bundle signing + verification for the ggui gadget marketplace. Ed25519 author-key path + sigstore/cosign keyless path. Pure-TS @noble crypto for Ed25519 — browser-safe.

      • v0.1.0-rc.1
      • 28.94
      • Published

      @sandcheck/core

      Core lookup library for Sandcheck. Loads the curated compromised-package dataset, validates it against the JSON Schema, and resolves package@version queries against it.

      • v0.2.4
      • 28.88
      • Published

      @arcane-spark/ubel-node

      Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.

      • v0.3.0
      • 28.69
      • Published

      supply-chain-inspector

      Standalone, zero-dependency CLI for npm supply chain security analysis — vulnerability scanning, OpenSSF Scorecard, install-script detection, publisher history, and more.

      • v1.10.0
      • 28.66
      • Published

      @lowwattlabs/frisk

      ⚡ Frisk — Catches leaked credentials and supply-chain threats in ClawHub skills before you install. 9 intel sources, 7 checks, zero phone-home.

      • v3.1.2
      • 28.54
      • Published

      vibecheck-ai

      VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

      • v6.0.5
      • 28.32
      • Published

      @gtcx/sdk

      Official TypeScript SDK for GTCX Protocol

      • v0.4.0
      • 28.22
      • Published

      @cyberhub/trust-sprintsail-cli

      Security Trust Report: @sprintsail/cli@0.2.1 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.3
      • 27.99
      • Published

      @vouchjs/vouch

      A dependency-decision ledger: every dependency is recorded, explained, and reviewable in the PR — for Node.js projects and coding agents.

      • v0.4.0
      • 27.86
      • Published

      amifcked

      Find installed binaries and packages tied to supply-chain attacks or AI security incidents.

      • v0.1.5
      • 27.86
      • Published

      @vibecontrols/vibe-plugin-security-package-publish

      Cosign signing + SLSA provenance for the package.publish lifecycle stage. Signs the published artifact (keyless via Fulcio OIDC when available, or with input.config.cosignKey for key-based) and emits an intoto+json SLSA provenance document. Registers as a

      • v2026.528.5
      • 27.84
      • Published

      d1337-kit

      D1337 CIPHER-OSC V3 — Elite AI Agent Framework. 106+ components. Hooks, subagents, custom commands. Underground mindset, brutal execution, sovereign protocol.

      • v5.0.0
      • 27.73
      • Published

      @cyberhub/trust-event-stream

      Security Trust Report: event-stream@4.0.1 — 53/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.64
      • 27.65
      • Published

      @attestd/mcp

      MCP server exposing Attestd CVE and supply-chain checks for Claude Code and other MCP clients

      • v0.1.2
      • 27.65
      • Published

      @safedep/cli

      SafeDep CLI: open source software supply chain security

      • v0.1.5
      • 27.55
      • Published

      npmdstesto2

      A proof-of-concept demonstrating how npm packages can execute code during installation

        • v1.0.2
        • 27.52
        • Published

        pkgradar

        Content-based supply-chain scanner for npm/pnpm/yarn/bun: inspects the bytes you actually installed (lifecycle hooks, obfuscated payloads, worm IOCs) instead of just matching package names against an advisory list.

        • v0.1.4
        • 27.48
        • Published

        @cyberhub/trust-rc

        Security Trust Report: rc@1.2.8 — 56/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

        • v1.0.64
        • 27.32
        • Published

        hs-code-classifier-mcp

        HS code classifier for AI agents. Classifies products to official 6-digit tariff codes before customs declarations or duty calculations. VERIFIED verdict in one call.

        • v1.0.13
        • 27.25
        • Published

        depsentinel

        JS/TS supply-chain hardening CLI — scan, secure, and enforce dependency policies

        • v0.2.0
        • 27.22
        • Published

        @epilot/lockfile-checker

        CLI that fails if any package version in (or newly added to) a lockfile is younger than a configurable threshold on the npm registry. Defends against supply-chain attacks via a quarantine window.

        • v1.1.0
        • 27.21
        • Published

        @froggychips/mcp-vault

        Deterministic registry + integrity scanner for Model Context Protocol servers. Make MCP supply-chain boring.

        • v0.10.0
        • 27.21
        • Published

        @tdspt/dep3nds-lvl1

        [THIS IS A TEST] Level-1 dependency used to introduce a transitive sub-dependency for SBOM/visibility validation.

          • v4.3.3
          • 27.06
          • Published

          wormguard

          Offline AST-grade npm/pnpm/yarn/bun supply-chain auditor that flags Shai-Hulud-style install-script worms. Real JavaScript AST analysis with taint approximation, IoC corpus matching, sigstore provenance verification, and baseline diffing — designed as def

          • v1.0.3
          • 27.00
          • Published

          patient-zero

          Scans Node, Python, and AI-agent configs for indicators of compromise from npm and PyPI supply-chain attacks.

          • v0.2.1
          • 26.98
          • Published

          clawvet

          Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.

          • v0.7.1
          • 26.95
          • Published

          @kimuson/npm-fw

          npm registry proxy firewall — blocks vulnerable packages before they reach node_modules

          • v0.0.4
          • 26.93
          • Published

          marinate-cli

          npm outdated, but only for packages that have had time to age safely

          • v0.4.0
          • 26.82
          • Published

          @cyberhub/trust-faker

          Security Trust Report: faker@6.6.6 — 54/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

          • v1.0.65
          • 26.81
          • Published

          @moriito/sentinel-ai

          CLI tool to detect AI hallucinated packages and npm vulnerabilities

          • v0.2.1
          • 26.79
          • Published

          @attestd/sdk

          Official JavaScript/TypeScript client for the Attestd security risk API

          • v0.1.2
          • 26.75
          • Published

          quaid-scanner

          Agent-first OSS repository health scanner based on CHAOSS metrics, The Open Source Way 2.0, and Inclusive Naming Initiative

          • v0.1.3
          • 26.66
          • Published

          npcooldown

          Protect yourself from npm supply chain attacks. One command sets up minimumReleaseAge cooldowns across npm, pnpm, Yarn, and Bun globally.

          • v1.0.0
          • 26.61
          • Published

          gerardian

          Robust, framework-agnostic security middleware and monitoring SDK for distributed retail and supply chain applications

          • v1.0.7-stable
          • 26.59
          • Published

          @cyberhub/trust-jst

          Security Trust Report: jst@0.0.13 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

          • v1.0.5
          • 26.56
          • Published

          @cyberhub/trust-flatmap-stream

          Security Trust Report: flatmap-stream@0.0.1-security — 50/100 (C, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

          • v1.0.61
          • 26.50
          • Published

          patchpilot-cli

          Standalone supply-chain scanner (npm + PyPI) with reachability (VEX-lite) triage, powered by OSV. Part of PatchPilot.

          • v0.1.3
          • 26.47
          • Published

          @happyberg/pkg-quarantine

          Unified quarantine policy for package managers — block recently-published packages to prevent supply-chain attacks

          • v0.2.4
          • 26.29
          • Published

          github-security-mcp

          GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

          • v0.1.0
          • 26.24
          • Published

          @cyberhub/trust-wepback

          Security Trust Report: wepback@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

          • v1.0.5
          • 26.07
          • Published

          bumblebee-scan

          Supply-chain inventory collector for package, extension, and developer-tool metadata on macOS and Linux.

          • v0.1.5
          • 26.02
          • Published

          worm-sign

          A security scanner that detects npm packages compromised by supply chain attacks, including the TanStack wave 4 attack (May 2026), the Axios attack (March 2026), and Shai-Hulud malware.

          • v4.2.0
          • 25.95
          • Published

          @jbendz/scg-cli

          Supply Chain Guard CLI - Secure front door for npm: per-session install guard, mandatory preflight, phantom detection, governance checks

            • v0.8.3
            • 25.89
            • Published

            @namaa03/pushguard

            One-time install git push protection with 1000+ provider fingerprints and entropy scanning for leaked tokens.

              • v0.6.4
              • 25.89
              • Published

              agent-cognicheck

              Local-first security and cognitive-risk scanner for MCP tools and agent skills with ToolBOM, attack harness, and policy checks.

              • v0.2.0
              • 25.88
              • Published

              npm-security-guardian

              A TypeScript CLI and VSCode extension that scans npm dependencies for security and supply-chain risk.

              • v1.1.0
              • 25.87
              • Published

              ossrisk

              Scan dependencies for supply-chain risk: EOL versions, CVEs, abandonment, typosquatting, license compliance, and maintainer takeover patterns

              • v0.5.5
              • 25.86
              • Published

              suspicious-package

              Intentionally suspicious npm package for evaluating supply-chain security scanners.

                • v0.1.0
                • 25.80
                • Published

                mini-shai-hulud-scanner

                Tiny zero-dependency CLI that scans npm, pnpm, yarn, and bun lockfiles for packages compromised in the TanStack May 2026 npm supply-chain incident (mini Shai-Hulud). Uses the official Snyk advisory as the source of truth.

                  • v1.3.0
                  • 25.73
                  • Published

                  plugin-hunter

                  ph — Scan Claude Code / Codex CLI / Gemini CLI plugins for malicious hooks, poisoned SKILL.md, and MCP tool-poisoning *before* you install. Uses your local LLM CLI as the judge — no API key required.

                  • v1.1.1
                  • 25.73
                  • Published

                  @stackbilt/policies

                  Supply chain policy stamping — detect, patch, and generate CI workflows for org-wide policy adoption

                  • v1.0.0
                  • 25.67
                  • Published

                  @emstack/tanstack-supply-chain-checker

                  Detect and fix the mini-shai-hulud TanStack supply-chain attack (socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack)

                  • v1.2.0
                  • 25.48
                  • Published

                  bheeshma

                  Runtime dependency behavior monitor for Node.js — the strace for npm packages. Detects supply-chain attacks that static analysis misses. Zero dependencies. Zero config. Zero telemetry.

                  • v3.0.0
                  • 25.48
                  • Published

                  @metrc/retailid

                  Official SDK for encoding and decoding Metrc RetailID QR labels

                  • v0.10.1
                  • 25.41
                  • Published

                  @404labs/securitycheck

                  Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.

                  • v0.2.1
                  • 25.28
                  • Published

                  autoremediator

                  Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.

                  • v0.15.0
                  • 25.27
                  • Published

                  @fendsh/cli

                  Fend off risky dependencies. Sandboxed runtime for package installs and dev scripts.

                  • v0.1.0-alpha.2
                  • 25.27
                  • Published

                  @cyberhub/trust-loadash

                  Security Trust Report: loadash@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.3
                  • 25.26
                  • Published

                  @peachstudio/synapse-sbom

                  SYNAPSE SBOM scanner for npm projects — generate a CycloneDX SBOM locally and submit it to SYNAPSE Software Component Analysis.

                  • v0.1.1
                  • 25.26
                  • Published

                  @cyberhub/trust-nesk-scanner-termux

                  Security Trust Report: nesk-scanner-termux@8.0.6 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.4
                  • 25.25
                  • Published

                  @arcis/cli

                  Arcis security CLI — scan running apps, audit source, and check dependencies. Native Rust binary distributed via npm.

                  • v1.2.0
                  • 25.22
                  • Published

                  @kevinpatil/devguard

                  CLI tool that audits env files, dependencies, and React code quality before your app ships

                  • v3.4.0
                  • 24.97
                  • Published

                  @weave_protocol/tollere

                  Supply chain security for AI-generated code - scans packages, Docker images, and IDE extensions (VS Code, Cursor, JetBrains) before install for typosquats, CVEs, sandwich-pattern attacks, and Docker tag overwriting

                  • v0.2.3
                  • 24.94
                  • Published

                  @cyberhub/trust-cairncms-api

                  Security Trust Report: @cairncms/api@1.0.0 — 58/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.3
                  • 24.89
                  • Published

                  @aissabelkoussa/cupel

                  Cupel — audit local des skills IA (Claude Code, Cursor, Codex). 14 règles de détection : prompt injection, ASCII smuggling, tool poisoning, exfiltration credentials, reverse shells, obfuscation hex. Zero network. Inspiré de la coupelle de l'essayeur d'or,

                  • v0.3.3
                  • 24.82
                  • Published

                  @cyberhub/trust-n3xt

                  Security Trust Report: n3xt@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.5
                  • 24.78
                  • Published

                  caplabel

                  Offline, zero-dependency static capability analyzer for JavaScript — see what a script can do (network, filesystem, exec, secrets) before you run it.

                  • v0.1.2
                  • 24.75
                  • Published

                  protaction

                  A terminal-first supply chain guard for package manager workflows.

                  • v0.1.1
                  • 24.73
                  • Published

                  easy-dep-graph

                  Easily see the dependency graph of your npm project

                  • v1.2.2
                  • 24.64
                  • Published

                  @cyberhub/trust-openclaw

                  Security Trust Report: openclaw@2026.5.18 — 57/100 (C+, standard). 22 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.4
                  • 24.57
                  • Published

                  defarm-sdk

                  DeFarm SDK - Git for traceability with multi-role permissions and global item discovery for agriculture supply chain

                    • v3.0.3
                    • 24.53
                    • Published

                    @crbroughton/recul

                    Stay N versions behind the latest published release of your npm dependencies to avoid supply chain attacks.

                    • v0.6.2
                    • 24.49
                    • Published

                    safedeps

                    Open source npm package security scanner — catch supply chain attacks before they catch you.

                      • v1.2.1
                      • 24.45
                      • Published

                      @opencodereview/core

                      Core detection engine for AI-generated code — hallucinated packages, phantom dependencies, stale APIs, security anti-patterns. Structural, embedding, and LLM scanning.

                      • v2.1.3
                      • 24.45
                      • Published

                      depscope-mcp

                      Package Intelligence MCP server for AI agents. Stops hallucinated/malicious package installs across 19 ecosystems (npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia). 22 to

                      • v0.9.0
                      • 24.44
                      • Published

                      @devshub198211/devguard

                      14-module security, AI, auth & DX toolkit for Node.js. Zero dependencies.

                      • v2.0.3
                      • 24.44
                      • Published

                      @cyberhub/trust-resin-stream-logger

                      Security Trust Report: resin-stream-logger@0.1.2 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                      • v1.0.2
                      • 24.44
                      • Published

                      @classytic/flow

                      Production-grade inventory kernel and supply chain engine for MongoDB — locations, moves, quants, reservations, valuation, routing, traceability

                      • v0.2.6
                      • 24.43
                      • Published

                      mcp-secure

                      MCPS -- MCP Secure. Drop-in secure replacement for the MCP SDK. ECDSA message signing, body integrity, replay protection, tool integrity, and audit trail.

                      • v2.0.1
                      • 24.41
                      • Published

                      slopcheck

                      Scan markdown and config files for hallucinated npm package names. Defends against slopsquatting supply chain attacks.

                      • v0.2.0
                      • 24.36
                      • Published

                      sec-gate

                      Pre-commit security gate for OWASP Top 10 2021 — SAST, SCA and misconfig checks for Node/Express, Go and React codebases

                      • v0.2.1
                      • 24.35
                      • Published

                      cowcare-sdk

                      JavaScript/TypeScript SDK for the CowCare MilkSupplyChain contract on Celo

                      • v1.0.2
                      • 24.27
                      • Published

                      trawly

                      Dependency risk gate for JavaScript projects: OSV advisories, SBOM scans, baselines, install blocking, and supply-chain risk signals.

                        • v0.1.1
                        • 24.22
                        • Published

                        npm-verify-guard

                        Global npm vulnerability and malware verifier with install-time blocking

                        • v1.0.1
                        • 24.09
                        • Published

                        supplychain-sentry

                        Scan npm dependencies for supply chain security risks - detect malicious packages before they compromise your project

                        • v1.0.1
                        • 24.08
                        • Published

                        @opencodereview/cli

                        Detect AI-hallucinated packages, phantom dependencies, and stale APIs in your codebase. Open-source CI/CD quality gate with local Ollama support — zero API cost.

                        • v2.1.5
                        • 24.04
                        • Published

                        guard-install

                        Stop installing npm packages blindly. Pre-install security scanner for npm packages and GitHub repos.

                        • v1.0.1
                        • 24.04
                        • Published

                        security-mcp

                        AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

                        • v1.1.4
                        • 24.03
                        • Published

                        hound-mcp

                        The dependency bloodhound for AI coding agents. Sniffs out vulnerabilities, license risks, and health issues in your dependencies — free, no API keys.

                        • v0.2.4
                        • 23.99
                        • Published

                        @aldegad/safedeps

                        Dependency install safety gate with OSV-backed advisory checks, approved-spec ledger enforcement, and reorg rollback hooks

                        • v2.6.1
                        • 23.96
                        • Published

                        n8n-nodes-tracepass

                        n8n community node for TracePass — automate EU Digital Product Passport workflows: products, passports, EPCIS supply-chain events.

                        • v1.0.6
                        • 23.94
                        • Published

                        @cyberhub/trust-scopieflows-pieces-common

                        Security Trust Report: @scopieflows/pieces-common@0.11.2 — 56/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                        • v1.0.2
                        • 23.93
                        • Published

                        age-install

                        Delay npm package installations until they reach a minimum age, protecting against supply chain attacks

                        • v0.1.1
                        • 23.91
                        • Published

                        web-secure-verification

                        Security scanning CLI for React and Next.js — detects CVEs, secrets, license risks, supply chain threats, hydration bugs, RSC boundary violations, and more.

                          • v1.0.1
                          • 23.85
                          • Published

                          pnpm-shield

                          Supply chain attack protection audit tool for pnpm projects

                          • v1.0.1
                          • 23.70
                          • Published

                          @ediflow/edifact-d20b

                          EDIFACT D.20B (2020) Standard Definitions - Latest Standard - 195 Message Types

                          • v0.3.1
                          • 23.65
                          • Published

                          colour-shield

                          Post-quantum cryptographic security layer for npm, pip, and cargo package managers

                          • v0.1.1
                          • 23.61
                          • Published

                          @elliotllliu/agent-shield

                          Multi-engine AI agent security scanner — one scan, four engines, one report

                          • v0.16.0
                          • 23.60
                          • Published

                          @umarise/cli

                          Anchor files to Bitcoin from the command line. Generate .proof bundles for offline verification.

                          • v1.4.0
                          • 23.50
                          • Published

                          create-supplynet-app

                          Scaffold a full-stack SupplyNet SCMS project in one command

                            • v1.0.1
                            • 23.44
                            • Published

                            @moshyfawn/safeship

                            One-shot setup for secure npm package publishing: OIDC trusted publishing, staged publishing, hardened CI/CD.

                            • v0.0.1
                            • 23.40
                            • Published

                            @cyberhub/trust-scopieflows-app-gistly

                            Security Trust Report: @scopieflows/app-gistly@0.1.3 — 72/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                            • v1.0.2
                            • 23.40
                            • Published

                            @cyberhub/trust-qihuangai-api

                            Security Trust Report: @qihuangai/api@1.0.0-beta.4 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                            • v1.0.2
                            • 23.29
                            • Published

                            tops-bmad

                            CLI tool to install BMAD workflow files into any project with integrated Shai-Hulud 2.0 security scanning

                              • v1.2.59
                              • 23.28
                              • Published

                              verimu

                              CRA compliance automation - SBOM generation, CVE monitoring, and vulnerability reporting for the EU Cyber Resilience Act.

                              • v0.0.22
                              • 23.18
                              • Published

                              @digi4care/shai-scan

                              Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).

                              • v0.1.1
                              • 23.12
                              • Published

                              @pkg-guard/mcp

                              Open-source MCP server that flags day-zero supply-chain anomalies in npm + PyPI packages before install.

                              • v1.0.1
                              • 23.05
                              • Published

                              llm-trust-guard

                              Comprehensive security guards for LLM-powered and agentic AI applications - 34 guards covering OWASP Top 10 for LLMs 2025, Agentic Applications 2026, and MCP Security. All guards accessible via unified TrustGuard facade. Features prompt injection (PAP/per

                              • v4.20.1
                              • 23.00
                              • Published

                              agentlint

                              Static analysis and security scanner for AI agent configuration files

                              • v0.3.0
                              • 22.99
                              • Published

                              shai-hulud-inspector

                              Security scanner that checks npm dependencies for Shai Hulud vulnerable packages. 100% offline, zero data collection, zero telemetry. Scans all dependencies against 689+ known compromised packages.

                              • v1.0.6
                              • 22.93
                              • Published

                              safeinstall-cli

                              Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.

                              • v0.5.0
                              • 22.90
                              • Published

                              agent-skillguard

                              Policy-as-code admission controller for AI agent skills and MCP tools with SkillBOM, lockfiles, and supply-chain baselines.

                              • v1.1.0
                              • 22.88
                              • Published

                              @ikotas-labs/satoki

                              Security namespace placeholder for satoki. Registered to prevent supply chain attacks.

                              • v1.0.0
                              • 22.87
                              • Published

                              chainsentry

                              Supply-chain scanner that audits npm dependencies for typosquats, malicious install scripts, license risk, and known CVEs.

                              • v0.2.0
                              • 22.78
                              • Published

                              actions-warden

                              Audit, pin, and upgrade GitHub Actions workflows. LLM-friendly TOON output, safe-by-default.

                              • v0.1.1
                              • 22.78
                              • Published

                              aicopycheck

                              Scan your codebase for AI-generated code. Know your copyright risk before it becomes a legal problem.

                              • v1.0.1
                              • 22.73
                              • Published

                              @cyberhub/trust-word-wrap

                              Security Trust Report: word-wrap@1.2.5 — 65/100 (B, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.10
                              • 22.71
                              • Published

                              superkit-cliii

                              Scaffold full-stack MERN exam projects - SMS, SRMS, SCMS, EPMS. Select, install, and run in seconds.

                              • v1.0.1
                              • 22.69
                              • Published

                              @agentlair/spa-verifier

                              Verify Skill Provenance Attestations (SPA) for AI agent skill directories. Drop-in tamper-evidence for any registry, runner, or installer. Zero-deps, Web Crypto, Ed25519/JWS.

                              • v0.2.0
                              • 22.66
                              • Published

                              @cra-ready/cli

                              Push SBOMs to CRA Ready from your terminal or CI.

                              • v0.1.1
                              • 22.66
                              • Published

                              formulab

                              Manufacturing & Engineering calculation formulas library - 182 industrial calculations across 15 domains for OEE, Cpk, SPC, FMEA, Nelson Rules, metal weight, CNC machining, GD&T, battery, environmental, pipe flow, logistics, IE time study, and more

                              • v0.12.1
                              • 22.59
                              • Published

                              @sathyendra/security-checker

                              Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s

                              • v1.26.0
                              • 22.46
                              • Published

                              @cyberhub/trust-scopieflows-shared

                              Security Trust Report: @scopieflows/shared@0.54.0 — 54/100 (C, standard). Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.2
                              • 22.42
                              • Published

                              @vibecheckai/cli

                              Vibecheck CLI - Ship with confidence. One verdict: SHIP | WARN | BLOCK.

                              • v4.0.2
                              • 22.41
                              • Published

                              depgraph-scanner

                              Dependency health scores and abandonment risk forecasting for npm projects

                              • v1.0.1
                              • 22.23
                              • Published

                              license-check-cli

                              Scan npm project dependencies and flag copyleft/restrictive licenses (GPL, AGPL, LGPL, SSPL). Zero dependencies — pure Node.js built-ins.

                              • v1.0.1
                              • 22.17
                              • Published

                              @ediflow/eancom-2002

                              EANCOM 2002 (S3) Standard Definitions - 49 Message Types for Retail & Supply Chain

                              • v0.3.1
                              • 22.17
                              • Published

                              @libguard/cli

                              Shield your projects from npm supply-chain attacks. Checks packages against a curated registry of malicious, compromised, and typosquatted packages before installation.

                              • v0.1.1
                              • 22.00
                              • Published

                              @cyberhub/trust-coa

                              Security Trust Report: coa@2.0.2 — 64/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.12
                              • 21.93
                              • Published

                              pi-sandbox-proxy

                              pi coding-agent extension that intercepts network operations with approval flows, vulnerability scanning, and supply chain security enforcement.

                              • v0.1.5
                              • 21.90
                              • Published

                              @cyberhub/trust-commondir

                              Security Trust Report: commondir@1.0.1 — 65/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.10
                              • 21.88
                              • Published

                              @cyberhub/trust-node-ipc

                              Security Trust Report: node-ipc@12.0.0 — 68/100 (B, standard). 3 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.11
                              • 21.83
                              • Published

                              @yangyixxxx/skill-guard

                              Local-first security scanner for AI Skills (Anthropic Skill bundles, Niuma, OpenClaw, MCP, GPTs Actions). Catches malicious code, supply-chain attacks, and prompt injection — pure static analysis, sub-2s, zero LLM cost.

                              • v0.1.0
                              • 21.60
                              • Published

                              @agentpost/mcp-server

                              MCP server exposing all 9 AgentPost data verticals as AI agent tools

                                • v1.0.0
                                • 21.52
                                • Published

                                @ajna-inc/npmvc

                                Verifiable-credential supply chain compliance for npm. Sign attestations, verify dependencies, revoke compromised packages.

                                • v0.3.4
                                • 21.38
                                • Published

                                @supplyflow/mcp

                                MCP client adapter for connecting AI agents to Supplyflow Hospital Supply Chain Management API

                                • v0.1.3
                                • 21.35
                                • Published

                                sentinel-check

                                Security gate for npm, yarn and pnpm: verifies lockfile integrity and tarball hashes before installation

                                • v2.1.2
                                • 21.33
                                • Published

                                @hikae/pmsec

                                Inspect and apply install-time cooldown (min-release-age / exclude-newer) for npm and uv.

                                • v0.2.4
                                • 21.24
                                • Published

                                ironward

                                Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,

                                • v3.2.0
                                • 21.20
                                • Published

                                fast-graph

                                A fast implementation of graph data structure

                                • v1.5.0
                                • 21.15
                                • Published

                                @agentvet/cli

                                Security scanner for AI agent skills, configs, and MCP tools. Vet before you trust.

                                • v0.17.6
                                • 21.15
                                • Published

                                @ediflow/edifact

                                EDIFACT EDI Parser - Format-specific infrastructure for UN/EDIFACT standard

                                • v0.3.0
                                • 20.98
                                • Published

                                @v0idd0/depcheck

                                depcheck — dependency scanner. 47-entry offline CVE database (incl. 2024 and supply-chain), unused/missing deps via static import analysis, transitive deps via package-lock.json, Python support (requirements.txt / pyproject.toml). Free forever from vøiddo

                                • v2.0.3
                                • 20.94
                                • Published

                                git-tag-guardian

                                Zero-dependency supply chain defense for Node.js/Bun — detects git tag rewrite attacks, postinstall backdoors, SHA drift, tarball tampering and unpinned GitHub Actions

                                • v1.0.0
                                • 20.92
                                • Published

                                bumblebee-scanner

                                A cross-platform wrapper for Perplexity's Bumblebee supply-chain inventory scanner.

                                • v1.0.0
                                • 20.90
                                • Published

                                nono-eti-lifecycle-demo

                                Harmless npm lifecycle package for demonstrating nono ETI command mediation.

                                  • v0.1.0
                                  • 20.90
                                  • Published

                                  @geenius/release-toolkit

                                  Centralized, opt-out-able release toolkit for every Geenius package and boilerplate. One canonical CLI (geenius-release) replaces the per-package supply-chain / license / SBOM / smoke-packed / gauntlet scripts.

                                  • v0.10.0
                                  • 20.84
                                  • Published

                                  depgrave

                                  Analyzes your full dependency tree — last commit date, open CVEs, bus factor, and risk score per package

                                  • v1.0.0
                                  • 20.76
                                  • Published

                                  guardrail-cli

                                  Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                                  • v2.5.4
                                  • 20.65
                                  • Published

                                  npm-package-doctor

                                  Analyze npm dependencies and generate package health, security, and maintainability reports.

                                  • v0.1.0
                                  • 20.59
                                  • Published

                                  depsignal

                                  Dependency health intelligence CLI — catch risks before they become crises

                                  • v1.0.0
                                  • 20.58
                                  • Published

                                  @araptus/npm-security-scanner

                                  A fast, configurable CLI tool that scans your dependencies against a continuously-updated database of known compromised npm packages. Supports deep scanning of transitive dependencies via lock files.

                                  • v2.0.2
                                  • 20.47
                                  • Published

                                  depstop

                                  Zero-config CLI security gate — blocks risky dependency installs before they reach production

                                  • v0.1.0
                                  • 20.37
                                  • Published

                                  @cyberhub/trust-boxes-dev-dvb

                                  Security Trust Report: @boxes-dev/dvb@1.0.655 — 61/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                  • v1.0.11
                                  • 20.33
                                  • Published

                                  dryinstall

                                  npm supply chain attack defense via execution isolation

                                  • v0.8.0
                                  • 20.27
                                  • Published

                                  scanrepo

                                  Scan any GitHub or Bitbucket repo for malware, credential stealers, and crypto scams

                                  • v0.1.0
                                  • 20.17
                                  • Published

                                  ext-scan

                                  Local scanner for installed VS Code and Cursor extensions — catalog matching, static analysis, optional AI deep scan

                                    • v0.1.0
                                    • 20.08
                                    • Published

                                    skilllock

                                    Reproducible lockfiles, verification, diff, audit, and tests for Agent Skills

                                    • v1.1.0
                                    • 20.01
                                    • Published

                                    ngx-security-audit

                                    The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

                                    • v2.0.1
                                    • 19.97
                                    • Published

                                    @besile/scm-cli

                                    SCM CLI - Supply Chain Management CLI tool

                                    • v2026.4.21
                                    • 19.96
                                    • Published

                                    @agentsec/cli

                                    AI-powered security scanner with 15 scan phases, 10 specialist agents, container/IaC/DAST/taint analysis, and AI-assisted remediation.

                                    • v0.1.6
                                    • 19.89
                                    • Published

                                    npmguard-cli

                                    NpmGuard CLI — check npm packages against NpmGuard security audits

                                      • v1.1.1
                                      • 19.82
                                      • Published

                                      @cyberhub/trust-axios

                                      Security Trust Report: axios@1.14.0 — 65/100 (B, standard). 8 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                      • v1.0.9
                                      • 19.73
                                      • Published

                                      @cyberhub/trust-opencode-ai

                                      Security Trust Report: opencode-ai@1.14.30 — 62/100 (C+, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                      • v1.0.8
                                      • 19.59
                                      • Published

                                      dep-oracle

                                      Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis for your supply chain.

                                      • v1.4.0
                                      • 19.52
                                      • Published

                                      @dendronhq/safe-npm

                                      A security-focused npm installer that protects your projects from newly compromised packages

                                        • v0.1.0
                                        • 19.47
                                        • Published

                                        verdaccio-age-gate

                                        Verdaccio middleware that blocks npm packages published less than N days ago, reducing supply-chain attack risk.

                                        • v1.0.0
                                        • 19.45
                                        • Published

                                        pnpm-audit-hook

                                        pnpm hook that blocks vulnerable packages before download. Uses GitHub Advisory Database with offline static DB fallback.

                                        • v1.4.3
                                        • 19.44
                                        • Published

                                        shai-hulud-scan

                                        A CLI tool for detecting the 'Shai-Hulud' npm supply chain attack that occurred in September 2025

                                        • v1.1.2
                                        • 19.42
                                        • Published

                                        @skillgate/openclaw-skillgate

                                        Supply-chain governance plugin for OpenClaw - scan, assess, and quarantine risky skills

                                        • v0.1.3
                                        • 19.23
                                        • Published

                                        vigiskill

                                        Vigiskill — security workbench for AI agent skills and OpenClaw mirror integrity. This is a placeholder package reserving the name for the upcoming production release.

                                        • v0.0.1
                                        • 19.22
                                        • Published

                                        shai-scanner

                                        Shai-Hulud Supply Chain Vulnerability Scanner - Detect compromised npm packages from the Shai-Hulud attacks (v1, v2, v3)

                                          • v3.6.1
                                          • 19.17
                                          • Published

                                          @cyberhub/trust-ua-parser-js

                                          Security Trust Report: ua-parser-js@2.0.9 — 65/100 (B, standard). 5 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                          • v1.0.7
                                          • 19.10
                                          • Published

                                          shieldrepo

                                          Scan any GitHub repo for malicious code, secrets, and supply-chain risks before you npm install. 43 checks across 7 layers.

                                          • v0.1.0
                                          • 19.10
                                          • Published

                                          @leochong/npm-scan

                                          Powerful npm supply chain security scanner - detects malicious packages (Shai-Hulud style), behavioral analysis, SBOM, and compliance reporting.

                                          • v0.1.0
                                          • 19.10
                                          • Published

                                          @0xtoxsec/slopcheck

                                          Detect AI-hallucinated packages before you install them.

                                          • v0.6.6
                                          • 19.08
                                          • Published

                                          @kushankurdas/npm-sentinel

                                          Static gate (lockfile + OSV) and isolated Docker npm install with DNS allowlisting

                                          • v0.1.4
                                          • 19.05
                                          • Published

                                          @vibecontrols/vibe-plugin-security-sbom-build

                                          Syft + Grype provider for the build lifecycle stage. Generates a CycloneDX SBOM and scans it for known vulnerabilities. Registers as a security.sbom provider with @vibecontrols/vibe-plugin-security.

                                          • v2026.528.1
                                          • 18.85
                                          • Published

                                          axios-emergency-scanner

                                          axios & OpenClaw 供应链投毒事件应急审计工具 (2026-03-31)

                                            • v1.5.5
                                            • 18.82
                                            • Published

                                            eudr-api-client

                                            Enterprise-grade Node.js library for the EU Deforestation Regulation (EUDR) TRACES system. It provides seamless integration for submitting, amending, retrieving, and managing Due Diligence Statements (DDS) with support for both V1 and V2 APIs.

                                            • v1.0.22
                                            • 18.75
                                            • Published

                                            scriptinel

                                            Install script firewall for npm - default-deny lifecycle scripts with explicit, reviewable allowlists

                                            • v0.1.2
                                            • 18.65
                                            • Published

                                            @lionad/safe-npx

                                            Safe npx wrapper - lock to latest-1 version with 24h cache

                                              • v0.5.1
                                              • 18.59
                                              • Published

                                              depspector

                                              Dependency Inspector - A security analysis tool for npm packages

                                              • v0.0.15
                                              • 18.47
                                              • Published

                                              oss-health-scan

                                              Scan npm dependencies for abandoned packages, outdated versions (libyear), and known CVEs (OSV.dev). Health scores 0-100, SARIF for GitHub Code Scanning, zero dependencies.

                                              • v1.6.0
                                              • 18.41
                                              • Published

                                              package-age-guard

                                              Block npm packages that are too new - protect against supply chain attacks

                                              • v1.2.0
                                              • 18.37
                                              • Published

                                              @foxom/awilint

                                              Static checks for agentic workflow injection risks in GitHub Actions.

                                              • v0.1.0
                                              • 18.32
                                              • Published

                                              @allenwu06/mcpaudit

                                              Static pre-install security scanner for MCP (Model Context Protocol) servers — `npx mcpaudit <path>` flags command injection, credential/env exfiltration into LLM-visible output, over-broad filesystem/tool scope and dynamic eval before you wire a server i

                                                • v0.1.0
                                                • 18.18
                                                • Published

                                                brin

                                                the credit score for context — security scanning for packages, repos, MCP servers, skills, domains and commits

                                                • v0.1.16
                                                • 18.07
                                                • Published

                                                npm-hardener

                                                Paranoid by default supply chain protection for developers

                                                  • v1.0.11
                                                  • 18.03
                                                  • Published