JSPM

Found 1210 results for supply-chain

@vibecontrols/vibe-plugin-security

Security lifecycle orchestrator — dispatches to per-stage security providers (secrets, sbom, release-gate, etc.).

  • v2026.601.3
  • 31.04
  • Published

@balkanbrs/munack-core

Core engine for detecting fake packages, fake imports, slopsquatting risk, and hallucinated dependencies in AI-generated code.

  • v0.1.12
  • 30.93
  • Published

sigild

Claude can sign, but never see. MCP server + CLI that keeps private keys out of the LLM's context window.

  • v0.0.8
  • 30.80
  • Published

@peac/mappings-slsa

SLSA v1.2 provenance mapping for PEAC provenance extension

  • v0.15.0
  • 30.79
  • Published

node-addon-slsa

Provenance verification for prebuilt native addons with GitHub attestations

  • v1.0.0
  • 30.78
  • Published

@peac/mappings-intoto

in-toto v1.0 attestation mapping for PEAC provenance extension

  • v0.15.0
  • 30.75
  • Published

execfence

Guard package-manager installs, dependency changes, CI, and agent-run commands before suspicious project code executes.

  • v5.0.2
  • 30.69
  • Published

npm-scan-plus

Security scanner for npm packages - pre and post-install scanning for malicious code, supply chain attacks, and obfuscated code

  • v1.1.1
  • 30.54
  • Published

infynon

Security-first CLI for AI-assisted development: safe package installs, dependency scanning, API flow testing, and agent task orchestration.

  • v0.2.12
  • 30.52
  • Published

ossguard

One CLI to guard any OSS project with OpenSSF security best practices — bootstrap, scan, and monitor.

  • v0.1.4
  • 30.47
  • Published

decoy-scan

Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.

  • v0.8.0
  • 30.06
  • Published

packsentry

npm dependency security scanner and package threat analysis tool

  • v2.1.1
  • 29.98
  • Published

trustdep

npm supply chain security scanner — detect typosquatting, maintainer changes, and malicious scripts before npm install

  • v1.2.2
  • 29.75
  • Published

sandcheck

Check your npm packages against a curated list of known-compromised versions. Scans package-lock.json, pnpm-lock.yaml, and yarn.lock. Built for the AI-coding era.

  • v0.2.5
  • 29.72
  • Published

@openagentlock/cli

OpenAgentLock CLI — a firewall for AI coding agents. Detects local agent harnesses (Claude Code, Codex CLI, Cursor, OpenCode, Cline, Gemini CLI, Continue, Copilot), gates risky tool calls via a Go control plane, anchors decisions in a Rust Merkle ledger.

  • v0.1.24
  • 29.67
  • Published

@nexus_js/audit

Nexus Dependency Auditor — OSV CVE scanning, offline cache, supply chain risk analysis, and build-time blocking

  • v0.9.30
  • 29.42
  • Published

@cyberhub/trust-colors

Security Trust Report: colors@1.4.0 — 46/100 (C, caution). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

  • v1.0.65
  • 29.34
  • Published

@sandcheck/mcp

Model Context Protocol server that lets AI coding assistants (Claude Code, Cursor, Windsurf) check npm packages against the Sandcheck dataset before suggesting installs.

  • v0.3.4
  • 29.22
  • Published

@flupkejs/cli

One command. Safer dependencies.

  • v1.3.0
  • 29.07
  • Published

kyos-cli

Bootstrap and safely evolve a shared Claude Code repo structure.

  • v1.1.0
  • 29.02
  • Published

exfil-poc

PoC package in npm for data exfil

  • v3.0.0
  • 29.00
  • Published

@ggui-ai/gadget-signing

Gadget bundle signing + verification for the ggui gadget marketplace. Ed25519 author-key path + sigstore/cosign keyless path. Pure-TS @noble crypto for Ed25519 — browser-safe.

  • v0.1.0-rc.1
  • 28.94
  • Published

@sandcheck/core

Core lookup library for Sandcheck. Loads the curated compromised-package dataset, validates it against the JSON Schema, and resolves package@version queries against it.

  • v0.2.4
  • 28.88
  • Published

@arcane-spark/ubel-node

Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.

  • v0.3.0
  • 28.69
  • Published

supply-chain-inspector

Standalone, zero-dependency CLI for npm supply chain security analysis — vulnerability scanning, OpenSSF Scorecard, install-script detection, publisher history, and more.

  • v1.10.0
  • 28.66
  • Published

@lowwattlabs/frisk

⚡ Frisk — Catches leaked credentials and supply-chain threats in ClawHub skills before you install. 9 intel sources, 7 checks, zero phone-home.

  • v3.1.2
  • 28.54
  • Published

vibecheck-ai

VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

  • v6.0.5
  • 28.32
  • Published

@gtcx/sdk

Official TypeScript SDK for GTCX Protocol

  • v0.4.0
  • 28.22
  • Published

@cyberhub/trust-sprintsail-cli

Security Trust Report: @sprintsail/cli@0.2.1 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

  • v1.0.3
  • 27.99
  • Published

@vouchjs/vouch

A dependency-decision ledger: every dependency is recorded, explained, and reviewable in the PR — for Node.js projects and coding agents.

  • v0.4.0
  • 27.86
  • Published

amifcked

Find installed binaries and packages tied to supply-chain attacks or AI security incidents.

  • v0.1.5
  • 27.86
  • Published

@vibecontrols/vibe-plugin-security-package-publish

Cosign signing + SLSA provenance for the package.publish lifecycle stage. Signs the published artifact (keyless via Fulcio OIDC when available, or with input.config.cosignKey for key-based) and emits an intoto+json SLSA provenance document. Registers as a

  • v2026.528.5
  • 27.84
  • Published

d1337-kit

D1337 CIPHER-OSC V3 — Elite AI Agent Framework. 106+ components. Hooks, subagents, custom commands. Underground mindset, brutal execution, sovereign protocol.

  • v5.0.0
  • 27.73
  • Published

@cyberhub/trust-event-stream

Security Trust Report: event-stream@4.0.1 — 53/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

  • v1.0.64
  • 27.65
  • Published

@attestd/mcp

MCP server exposing Attestd CVE and supply-chain checks for Claude Code and other MCP clients

  • v0.1.2
  • 27.65
  • Published

@safedep/cli

SafeDep CLI: open source software supply chain security

  • v0.1.5
  • 27.55
  • Published

npmdstesto2

A proof-of-concept demonstrating how npm packages can execute code during installation

    • v1.0.2
    • 27.52
    • Published

    pkgradar

    Content-based supply-chain scanner for npm/pnpm/yarn/bun: inspects the bytes you actually installed (lifecycle hooks, obfuscated payloads, worm IOCs) instead of just matching package names against an advisory list.

    • v0.1.4
    • 27.48
    • Published

    @cyberhub/trust-rc

    Security Trust Report: rc@1.2.8 — 56/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

    • v1.0.64
    • 27.32
    • Published

    hs-code-classifier-mcp

    HS code classifier for AI agents. Classifies products to official 6-digit tariff codes before customs declarations or duty calculations. VERIFIED verdict in one call.

    • v1.0.13
    • 27.25
    • Published

    depsentinel

    JS/TS supply-chain hardening CLI — scan, secure, and enforce dependency policies

    • v0.2.0
    • 27.22
    • Published

    @epilot/lockfile-checker

    CLI that fails if any package version in (or newly added to) a lockfile is younger than a configurable threshold on the npm registry. Defends against supply-chain attacks via a quarantine window.

    • v1.1.0
    • 27.21
    • Published

    @froggychips/mcp-vault

    Deterministic registry + integrity scanner for Model Context Protocol servers. Make MCP supply-chain boring.

    • v0.10.0
    • 27.21
    • Published

    @tdspt/dep3nds-lvl1

    [THIS IS A TEST] Level-1 dependency used to introduce a transitive sub-dependency for SBOM/visibility validation.

      • v4.3.3
      • 27.06
      • Published

      wormguard

      Offline AST-grade npm/pnpm/yarn/bun supply-chain auditor that flags Shai-Hulud-style install-script worms. Real JavaScript AST analysis with taint approximation, IoC corpus matching, sigstore provenance verification, and baseline diffing — designed as def

      • v1.0.3
      • 27.00
      • Published

      patient-zero

      Scans Node, Python, and AI-agent configs for indicators of compromise from npm and PyPI supply-chain attacks.

      • v0.2.1
      • 26.98
      • Published

      clawvet

      Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.

      • v0.7.1
      • 26.95
      • Published

      @kimuson/npm-fw

      npm registry proxy firewall — blocks vulnerable packages before they reach node_modules

      • v0.0.4
      • 26.93
      • Published

      marinate-cli

      npm outdated, but only for packages that have had time to age safely

      • v0.4.0
      • 26.82
      • Published

      @cyberhub/trust-faker

      Security Trust Report: faker@6.6.6 — 54/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.65
      • 26.81
      • Published

      @moriito/sentinel-ai

      CLI tool to detect AI hallucinated packages and npm vulnerabilities

      • v0.2.1
      • 26.79
      • Published

      @attestd/sdk

      Official JavaScript/TypeScript client for the Attestd security risk API

      • v0.1.2
      • 26.75
      • Published

      quaid-scanner

      Agent-first OSS repository health scanner based on CHAOSS metrics, The Open Source Way 2.0, and Inclusive Naming Initiative

      • v0.1.3
      • 26.66
      • Published

      npcooldown

      Protect yourself from npm supply chain attacks. One command sets up minimumReleaseAge cooldowns across npm, pnpm, Yarn, and Bun globally.

      • v1.0.0
      • 26.61
      • Published

      gerardian

      Robust, framework-agnostic security middleware and monitoring SDK for distributed retail and supply chain applications

      • v1.0.7-stable
      • 26.59
      • Published

      @cyberhub/trust-jst

      Security Trust Report: jst@0.0.13 — 59/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.5
      • 26.56
      • Published

      @cyberhub/trust-flatmap-stream

      Security Trust Report: flatmap-stream@0.0.1-security — 50/100 (C, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.61
      • 26.50
      • Published

      patchpilot-cli

      Standalone supply-chain scanner (npm + PyPI) with reachability (VEX-lite) triage, powered by OSV. Part of PatchPilot.

      • v0.1.3
      • 26.47
      • Published

      @happyberg/pkg-quarantine

      Unified quarantine policy for package managers — block recently-published packages to prevent supply-chain attacks

      • v0.2.4
      • 26.29
      • Published

      github-security-mcp

      GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

      • v0.1.0
      • 26.24
      • Published

      @cyberhub/trust-wepback

      Security Trust Report: wepback@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

      • v1.0.5
      • 26.07
      • Published

      bumblebee-scan

      Supply-chain inventory collector for package, extension, and developer-tool metadata on macOS and Linux.

      • v0.1.5
      • 26.02
      • Published

      worm-sign

      A security scanner that detects npm packages compromised by supply chain attacks, including the TanStack wave 4 attack (May 2026), the Axios attack (March 2026), and Shai-Hulud malware.

      • v4.2.0
      • 25.95
      • Published

      @jbendz/scg-cli

      Supply Chain Guard CLI - Secure front door for npm: per-session install guard, mandatory preflight, phantom detection, governance checks

        • v0.8.3
        • 25.89
        • Published

        @namaa03/pushguard

        One-time install git push protection with 1000+ provider fingerprints and entropy scanning for leaked tokens.

          • v0.6.4
          • 25.89
          • Published

          agent-cognicheck

          Local-first security and cognitive-risk scanner for MCP tools and agent skills with ToolBOM, attack harness, and policy checks.

          • v0.2.0
          • 25.88
          • Published

          npm-security-guardian

          A TypeScript CLI and VSCode extension that scans npm dependencies for security and supply-chain risk.

          • v1.1.0
          • 25.87
          • Published

          ossrisk

          Scan dependencies for supply-chain risk: EOL versions, CVEs, abandonment, typosquatting, license compliance, and maintainer takeover patterns

          • v0.5.5
          • 25.86
          • Published

          suspicious-package

          Intentionally suspicious npm package for evaluating supply-chain security scanners.

            • v0.1.0
            • 25.80
            • Published

            mini-shai-hulud-scanner

            Tiny zero-dependency CLI that scans npm, pnpm, yarn, and bun lockfiles for packages compromised in the TanStack May 2026 npm supply-chain incident (mini Shai-Hulud). Uses the official Snyk advisory as the source of truth.

              • v1.3.0
              • 25.73
              • Published

              plugin-hunter

              ph — Scan Claude Code / Codex CLI / Gemini CLI plugins for malicious hooks, poisoned SKILL.md, and MCP tool-poisoning *before* you install. Uses your local LLM CLI as the judge — no API key required.

              • v1.1.1
              • 25.73
              • Published

              @stackbilt/policies

              Supply chain policy stamping — detect, patch, and generate CI workflows for org-wide policy adoption

              • v1.0.0
              • 25.67
              • Published

              @emstack/tanstack-supply-chain-checker

              Detect and fix the mini-shai-hulud TanStack supply-chain attack (socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack)

              • v1.2.0
              • 25.48
              • Published

              bheeshma

              Runtime dependency behavior monitor for Node.js — the strace for npm packages. Detects supply-chain attacks that static analysis misses. Zero dependencies. Zero config. Zero telemetry.

              • v3.0.0
              • 25.48
              • Published

              @metrc/retailid

              Official SDK for encoding and decoding Metrc RetailID QR labels

              • v0.10.1
              • 25.41
              • Published

              @404labs/securitycheck

              Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.

              • v0.2.1
              • 25.28
              • Published

              autoremediator

              Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.

              • v0.15.0
              • 25.27
              • Published

              @fendsh/cli

              Fend off risky dependencies. Sandboxed runtime for package installs and dev scripts.

              • v0.1.0-alpha.2
              • 25.27
              • Published

              @cyberhub/trust-loadash

              Security Trust Report: loadash@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

              • v1.0.3
              • 25.26
              • Published

              @peachstudio/synapse-sbom

              SYNAPSE SBOM scanner for npm projects — generate a CycloneDX SBOM locally and submit it to SYNAPSE Software Component Analysis.

              • v0.1.1
              • 25.26
              • Published

              @cyberhub/trust-nesk-scanner-termux

              Security Trust Report: nesk-scanner-termux@8.0.6 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

              • v1.0.4
              • 25.25
              • Published

              @arcis/cli

              Arcis security CLI — scan running apps, audit source, and check dependencies. Native Rust binary distributed via npm.

              • v1.2.0
              • 25.22
              • Published

              @kevinpatil/devguard

              CLI tool that audits env files, dependencies, and React code quality before your app ships

              • v3.4.0
              • 24.97
              • Published

              @weave_protocol/tollere

              Supply chain security for AI-generated code - scans packages, Docker images, and IDE extensions (VS Code, Cursor, JetBrains) before install for typosquats, CVEs, sandwich-pattern attacks, and Docker tag overwriting

              • v0.2.3
              • 24.94
              • Published

              @cyberhub/trust-cairncms-api

              Security Trust Report: @cairncms/api@1.0.0 — 58/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

              • v1.0.3
              • 24.89
              • Published

              @aissabelkoussa/cupel

              Cupel — audit local des skills IA (Claude Code, Cursor, Codex). 14 règles de détection : prompt injection, ASCII smuggling, tool poisoning, exfiltration credentials, reverse shells, obfuscation hex. Zero network. Inspiré de la coupelle de l'essayeur d'or,

              • v0.3.3
              • 24.82
              • Published

              @cyberhub/trust-n3xt

              Security Trust Report: n3xt@1.0.0 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

              • v1.0.5
              • 24.78
              • Published

              caplabel

              Offline, zero-dependency static capability analyzer for JavaScript — see what a script can do (network, filesystem, exec, secrets) before you run it.

              • v0.1.2
              • 24.75
              • Published

              protaction

              A terminal-first supply chain guard for package manager workflows.

              • v0.1.1
              • 24.73
              • Published

              easy-dep-graph

              Easily see the dependency graph of your npm project

              • v1.2.2
              • 24.64
              • Published

              @cyberhub/trust-openclaw

              Security Trust Report: openclaw@2026.5.18 — 57/100 (C+, standard). 22 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

              • v1.0.4
              • 24.57
              • Published

              defarm-sdk

              DeFarm SDK - Git for traceability with multi-role permissions and global item discovery for agriculture supply chain

                • v3.0.3
                • 24.53
                • Published

                @crbroughton/recul

                Stay N versions behind the latest published release of your npm dependencies to avoid supply chain attacks.

                • v0.6.2
                • 24.49
                • Published

                safedeps

                Open source npm package security scanner — catch supply chain attacks before they catch you.

                  • v1.2.1
                  • 24.45
                  • Published

                  @opencodereview/core

                  Core detection engine for AI-generated code — hallucinated packages, phantom dependencies, stale APIs, security anti-patterns. Structural, embedding, and LLM scanning.

                  • v2.1.3
                  • 24.45
                  • Published

                  depscope-mcp

                  Package Intelligence MCP server for AI agents. Stops hallucinated/malicious package installs across 19 ecosystems (npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia). 22 to

                  • v0.9.0
                  • 24.44
                  • Published

                  @devshub198211/devguard

                  14-module security, AI, auth & DX toolkit for Node.js. Zero dependencies.

                  • v2.0.3
                  • 24.44
                  • Published

                  @cyberhub/trust-resin-stream-logger

                  Security Trust Report: resin-stream-logger@0.1.2 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                  • v1.0.2
                  • 24.44
                  • Published

                  @classytic/flow

                  Production-grade inventory kernel and supply chain engine for MongoDB — locations, moves, quants, reservations, valuation, routing, traceability

                  • v0.2.6
                  • 24.43
                  • Published

                  mcp-secure

                  MCPS -- MCP Secure. Drop-in secure replacement for the MCP SDK. ECDSA message signing, body integrity, replay protection, tool integrity, and audit trail.

                  • v2.0.1
                  • 24.41
                  • Published

                  slopcheck

                  Scan markdown and config files for hallucinated npm package names. Defends against slopsquatting supply chain attacks.

                  • v0.2.0
                  • 24.36
                  • Published

                  sec-gate

                  Pre-commit security gate for OWASP Top 10 2021 — SAST, SCA and misconfig checks for Node/Express, Go and React codebases

                  • v0.2.1
                  • 24.35
                  • Published

                  cowcare-sdk

                  JavaScript/TypeScript SDK for the CowCare MilkSupplyChain contract on Celo

                  • v1.0.2
                  • 24.27
                  • Published

                  trawly

                  Dependency risk gate for JavaScript projects: OSV advisories, SBOM scans, baselines, install blocking, and supply-chain risk signals.

                    • v0.1.1
                    • 24.22
                    • Published

                    npm-verify-guard

                    Global npm vulnerability and malware verifier with install-time blocking

                    • v1.0.1
                    • 24.09
                    • Published

                    supplychain-sentry

                    Scan npm dependencies for supply chain security risks - detect malicious packages before they compromise your project

                    • v1.0.1
                    • 24.08
                    • Published

                    @opencodereview/cli

                    Detect AI-hallucinated packages, phantom dependencies, and stale APIs in your codebase. Open-source CI/CD quality gate with local Ollama support — zero API cost.

                    • v2.1.5
                    • 24.04
                    • Published

                    guard-install

                    Stop installing npm packages blindly. Pre-install security scanner for npm packages and GitHub repos.

                    • v1.0.1
                    • 24.04
                    • Published

                    security-mcp

                    AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

                    • v1.1.4
                    • 24.03
                    • Published

                    hound-mcp

                    The dependency bloodhound for AI coding agents. Sniffs out vulnerabilities, license risks, and health issues in your dependencies — free, no API keys.

                    • v0.2.4
                    • 23.99
                    • Published

                    @aldegad/safedeps

                    Dependency install safety gate with OSV-backed advisory checks, approved-spec ledger enforcement, and reorg rollback hooks

                    • v2.6.1
                    • 23.96
                    • Published

                    n8n-nodes-tracepass

                    n8n community node for TracePass — automate EU Digital Product Passport workflows: products, passports, EPCIS supply-chain events.

                    • v1.0.6
                    • 23.94
                    • Published

                    @cyberhub/trust-scopieflows-pieces-common

                    Security Trust Report: @scopieflows/pieces-common@0.11.2 — 56/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                    • v1.0.2
                    • 23.93
                    • Published

                    age-install

                    Delay npm package installations until they reach a minimum age, protecting against supply chain attacks

                    • v0.1.1
                    • 23.91
                    • Published

                    web-secure-verification

                    Security scanning CLI for React and Next.js — detects CVEs, secrets, license risks, supply chain threats, hydration bugs, RSC boundary violations, and more.

                      • v1.0.1
                      • 23.85
                      • Published

                      pnpm-shield

                      Supply chain attack protection audit tool for pnpm projects

                      • v1.0.1
                      • 23.70
                      • Published

                      @ediflow/edifact-d20b

                      EDIFACT D.20B (2020) Standard Definitions - Latest Standard - 195 Message Types

                      • v0.3.1
                      • 23.65
                      • Published

                      colour-shield

                      Post-quantum cryptographic security layer for npm, pip, and cargo package managers

                      • v0.1.1
                      • 23.61
                      • Published

                      @elliotllliu/agent-shield

                      Multi-engine AI agent security scanner — one scan, four engines, one report

                      • v0.16.0
                      • 23.60
                      • Published

                      @umarise/cli

                      Anchor files to Bitcoin from the command line. Generate .proof bundles for offline verification.

                      • v1.4.0
                      • 23.50
                      • Published

                      create-supplynet-app

                      Scaffold a full-stack SupplyNet SCMS project in one command

                        • v1.0.1
                        • 23.44
                        • Published

                        @moshyfawn/safeship

                        One-shot setup for secure npm package publishing: OIDC trusted publishing, staged publishing, hardened CI/CD.

                        • v0.0.1
                        • 23.40
                        • Published

                        @cyberhub/trust-scopieflows-app-gistly

                        Security Trust Report: @scopieflows/app-gistly@0.1.3 — 72/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                        • v1.0.2
                        • 23.40
                        • Published

                        @cyberhub/trust-qihuangai-api

                        Security Trust Report: @qihuangai/api@1.0.0-beta.4 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                        • v1.0.2
                        • 23.29
                        • Published

                        tops-bmad

                        CLI tool to install BMAD workflow files into any project with integrated Shai-Hulud 2.0 security scanning

                          • v1.2.59
                          • 23.28
                          • Published

                          verimu

                          CRA compliance automation - SBOM generation, CVE monitoring, and vulnerability reporting for the EU Cyber Resilience Act.

                          • v0.0.22
                          • 23.18
                          • Published

                          @digi4care/shai-scan

                          Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like Mini Shai-Hulud (CVE-2026-45321).

                          • v0.1.1
                          • 23.12
                          • Published

                          @pkg-guard/mcp

                          Open-source MCP server that flags day-zero supply-chain anomalies in npm + PyPI packages before install.

                          • v1.0.1
                          • 23.05
                          • Published

                          llm-trust-guard

                          Comprehensive security guards for LLM-powered and agentic AI applications - 34 guards covering OWASP Top 10 for LLMs 2025, Agentic Applications 2026, and MCP Security. All guards accessible via unified TrustGuard facade. Features prompt injection (PAP/per

                          • v4.20.1
                          • 23.00
                          • Published

                          agentlint

                          Static analysis and security scanner for AI agent configuration files

                          • v0.3.0
                          • 22.99
                          • Published

                          shai-hulud-inspector

                          Security scanner that checks npm dependencies for Shai Hulud vulnerable packages. 100% offline, zero data collection, zero telemetry. Scans all dependencies against 689+ known compromised packages.

                          • v1.0.6
                          • 22.93
                          • Published

                          safeinstall-cli

                          Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.

                          • v0.5.0
                          • 22.90
                          • Published

                          agent-skillguard

                          Policy-as-code admission controller for AI agent skills and MCP tools with SkillBOM, lockfiles, and supply-chain baselines.

                          • v1.1.0
                          • 22.88
                          • Published

                          @ikotas-labs/satoki

                          Security namespace placeholder for satoki. Registered to prevent supply chain attacks.

                          • v1.0.0
                          • 22.87
                          • Published

                          chainsentry

                          Supply-chain scanner that audits npm dependencies for typosquats, malicious install scripts, license risk, and known CVEs.

                          • v0.2.0
                          • 22.78
                          • Published

                          actions-warden

                          Audit, pin, and upgrade GitHub Actions workflows. LLM-friendly TOON output, safe-by-default.

                          • v0.1.1
                          • 22.78
                          • Published

                          aicopycheck

                          Scan your codebase for AI-generated code. Know your copyright risk before it becomes a legal problem.

                          • v1.0.1
                          • 22.73
                          • Published

                          @cyberhub/trust-word-wrap

                          Security Trust Report: word-wrap@1.2.5 — 65/100 (B, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.10
                          • 22.71
                          • Published

                          superkit-cliii

                          Scaffold full-stack MERN exam projects - SMS, SRMS, SCMS, EPMS. Select, install, and run in seconds.

                          • v1.0.1
                          • 22.69
                          • Published

                          @agentlair/spa-verifier

                          Verify Skill Provenance Attestations (SPA) for AI agent skill directories. Drop-in tamper-evidence for any registry, runner, or installer. Zero-deps, Web Crypto, Ed25519/JWS.

                          • v0.2.0
                          • 22.66
                          • Published

                          @cra-ready/cli

                          Push SBOMs to CRA Ready from your terminal or CI.

                          • v0.1.1
                          • 22.66
                          • Published

                          formulab

                          Manufacturing & Engineering calculation formulas library - 182 industrial calculations across 15 domains for OEE, Cpk, SPC, FMEA, Nelson Rules, metal weight, CNC machining, GD&T, battery, environmental, pipe flow, logistics, IE time study, and more

                          • v0.12.1
                          • 22.59
                          • Published

                          @sathyendra/security-checker

                          Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s

                          • v1.26.0
                          • 22.46
                          • Published

                          @cyberhub/trust-scopieflows-shared

                          Security Trust Report: @scopieflows/shared@0.54.0 — 54/100 (C, standard). Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.2
                          • 22.42
                          • Published

                          @vibecheckai/cli

                          Vibecheck CLI - Ship with confidence. One verdict: SHIP | WARN | BLOCK.

                          • v4.0.2
                          • 22.41
                          • Published

                          depgraph-scanner

                          Dependency health scores and abandonment risk forecasting for npm projects

                          • v1.0.1
                          • 22.23
                          • Published

                          license-check-cli

                          Scan npm project dependencies and flag copyleft/restrictive licenses (GPL, AGPL, LGPL, SSPL). Zero dependencies — pure Node.js built-ins.

                          • v1.0.1
                          • 22.17
                          • Published

                          @ediflow/eancom-2002

                          EANCOM 2002 (S3) Standard Definitions - 49 Message Types for Retail & Supply Chain

                          • v0.3.1
                          • 22.17
                          • Published

                          @libguard/cli

                          Shield your projects from npm supply-chain attacks. Checks packages against a curated registry of malicious, compromised, and typosquatted packages before installation.

                          • v0.1.1
                          • 22.00
                          • Published

                          @cyberhub/trust-coa

                          Security Trust Report: coa@2.0.2 — 64/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.12
                          • 21.93
                          • Published

                          pi-sandbox-proxy

                          pi coding-agent extension that intercepts network operations with approval flows, vulnerability scanning, and supply chain security enforcement.

                          • v0.1.5
                          • 21.90
                          • Published

                          @cyberhub/trust-commondir

                          Security Trust Report: commondir@1.0.1 — 65/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.10
                          • 21.88
                          • Published

                          @cyberhub/trust-node-ipc

                          Security Trust Report: node-ipc@12.0.0 — 68/100 (B, standard). 3 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                          • v1.0.11
                          • 21.83
                          • Published

                          @yangyixxxx/skill-guard

                          Local-first security scanner for AI Skills (Anthropic Skill bundles, Niuma, OpenClaw, MCP, GPTs Actions). Catches malicious code, supply-chain attacks, and prompt injection — pure static analysis, sub-2s, zero LLM cost.

                          • v0.1.0
                          • 21.60
                          • Published

                          @agentpost/mcp-server

                          MCP server exposing all 9 AgentPost data verticals as AI agent tools

                            • v1.0.0
                            • 21.52
                            • Published

                            @ajna-inc/npmvc

                            Verifiable-credential supply chain compliance for npm. Sign attestations, verify dependencies, revoke compromised packages.

                            • v0.3.4
                            • 21.38
                            • Published

                            @supplyflow/mcp

                            MCP client adapter for connecting AI agents to Supplyflow Hospital Supply Chain Management API

                            • v0.1.3
                            • 21.35
                            • Published

                            sentinel-check

                            Security gate for npm, yarn and pnpm: verifies lockfile integrity and tarball hashes before installation

                            • v2.1.2
                            • 21.33
                            • Published

                            @hikae/pmsec

                            Inspect and apply install-time cooldown (min-release-age / exclude-newer) for npm and uv.

                            • v0.2.4
                            • 21.24
                            • Published

                            ironward

                            Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,

                            • v3.2.0
                            • 21.20
                            • Published

                            fast-graph

                            A fast implementation of graph data structure

                            • v1.5.0
                            • 21.15
                            • Published

                            @agentvet/cli

                            Security scanner for AI agent skills, configs, and MCP tools. Vet before you trust.

                            • v0.17.6
                            • 21.15
                            • Published

                            @ediflow/edifact

                            EDIFACT EDI Parser - Format-specific infrastructure for UN/EDIFACT standard

                            • v0.3.0
                            • 20.98
                            • Published

                            @v0idd0/depcheck

                            depcheck — dependency scanner. 47-entry offline CVE database (incl. 2024 and supply-chain), unused/missing deps via static import analysis, transitive deps via package-lock.json, Python support (requirements.txt / pyproject.toml). Free forever from vøiddo

                            • v2.0.3
                            • 20.94
                            • Published

                            git-tag-guardian

                            Zero-dependency supply chain defense for Node.js/Bun — detects git tag rewrite attacks, postinstall backdoors, SHA drift, tarball tampering and unpinned GitHub Actions

                            • v1.0.0
                            • 20.92
                            • Published

                            bumblebee-scanner

                            A cross-platform wrapper for Perplexity's Bumblebee supply-chain inventory scanner.

                            • v1.0.0
                            • 20.90
                            • Published

                            nono-eti-lifecycle-demo

                            Harmless npm lifecycle package for demonstrating nono ETI command mediation.

                              • v0.1.0
                              • 20.90
                              • Published

                              @geenius/release-toolkit

                              Centralized, opt-out-able release toolkit for every Geenius package and boilerplate. One canonical CLI (geenius-release) replaces the per-package supply-chain / license / SBOM / smoke-packed / gauntlet scripts.

                              • v0.10.0
                              • 20.84
                              • Published

                              depgrave

                              Analyzes your full dependency tree — last commit date, open CVEs, bus factor, and risk score per package

                              • v1.0.0
                              • 20.76
                              • Published

                              guardrail-cli

                              Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                              • v2.5.4
                              • 20.65
                              • Published

                              npm-package-doctor

                              Analyze npm dependencies and generate package health, security, and maintainability reports.

                              • v0.1.0
                              • 20.59
                              • Published

                              depsignal

                              Dependency health intelligence CLI — catch risks before they become crises

                              • v1.0.0
                              • 20.58
                              • Published

                              @araptus/npm-security-scanner

                              A fast, configurable CLI tool that scans your dependencies against a continuously-updated database of known compromised npm packages. Supports deep scanning of transitive dependencies via lock files.

                              • v2.0.2
                              • 20.47
                              • Published

                              depstop

                              Zero-config CLI security gate — blocks risky dependency installs before they reach production

                              • v0.1.0
                              • 20.37
                              • Published

                              @cyberhub/trust-boxes-dev-dvb

                              Security Trust Report: @boxes-dev/dvb@1.0.655 — 61/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                              • v1.0.11
                              • 20.33
                              • Published

                              dryinstall

                              npm supply chain attack defense via execution isolation

                              • v0.8.0
                              • 20.27
                              • Published

                              scanrepo

                              Scan any GitHub or Bitbucket repo for malware, credential stealers, and crypto scams

                              • v0.1.0
                              • 20.17
                              • Published

                              ext-scan

                              Local scanner for installed VS Code and Cursor extensions — catalog matching, static analysis, optional AI deep scan

                                • v0.1.0
                                • 20.08
                                • Published

                                skilllock

                                Reproducible lockfiles, verification, diff, audit, and tests for Agent Skills

                                • v1.1.0
                                • 20.01
                                • Published

                                ngx-security-audit

                                The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

                                • v2.0.1
                                • 19.97
                                • Published

                                @besile/scm-cli

                                SCM CLI - Supply Chain Management CLI tool

                                • v2026.4.21
                                • 19.96
                                • Published

                                @agentsec/cli

                                AI-powered security scanner with 15 scan phases, 10 specialist agents, container/IaC/DAST/taint analysis, and AI-assisted remediation.

                                • v0.1.6
                                • 19.89
                                • Published

                                npmguard-cli

                                NpmGuard CLI — check npm packages against NpmGuard security audits

                                  • v1.1.1
                                  • 19.82
                                  • Published

                                  @cyberhub/trust-axios

                                  Security Trust Report: axios@1.14.0 — 65/100 (B, standard). 8 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                  • v1.0.9
                                  • 19.73
                                  • Published

                                  @cyberhub/trust-opencode-ai

                                  Security Trust Report: opencode-ai@1.14.30 — 62/100 (C+, standard). 2 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                  • v1.0.8
                                  • 19.59
                                  • Published

                                  dep-oracle

                                  Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis for your supply chain.

                                  • v1.4.0
                                  • 19.52
                                  • Published

                                  @dendronhq/safe-npm

                                  A security-focused npm installer that protects your projects from newly compromised packages

                                    • v0.1.0
                                    • 19.47
                                    • Published

                                    verdaccio-age-gate

                                    Verdaccio middleware that blocks npm packages published less than N days ago, reducing supply-chain attack risk.

                                    • v1.0.0
                                    • 19.45
                                    • Published

                                    pnpm-audit-hook

                                    pnpm hook that blocks vulnerable packages before download. Uses GitHub Advisory Database with offline static DB fallback.

                                    • v1.4.3
                                    • 19.44
                                    • Published

                                    shai-hulud-scan

                                    A CLI tool for detecting the 'Shai-Hulud' npm supply chain attack that occurred in September 2025

                                    • v1.1.2
                                    • 19.42
                                    • Published

                                    @skillgate/openclaw-skillgate

                                    Supply-chain governance plugin for OpenClaw - scan, assess, and quarantine risky skills

                                    • v0.1.3
                                    • 19.23
                                    • Published

                                    vigiskill

                                    Vigiskill — security workbench for AI agent skills and OpenClaw mirror integrity. This is a placeholder package reserving the name for the upcoming production release.

                                    • v0.0.1
                                    • 19.22
                                    • Published

                                    shai-scanner

                                    Shai-Hulud Supply Chain Vulnerability Scanner - Detect compromised npm packages from the Shai-Hulud attacks (v1, v2, v3)

                                      • v3.6.1
                                      • 19.17
                                      • Published

                                      @cyberhub/trust-ua-parser-js

                                      Security Trust Report: ua-parser-js@2.0.9 — 65/100 (B, standard). 5 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.

                                      • v1.0.7
                                      • 19.10
                                      • Published

                                      shieldrepo

                                      Scan any GitHub repo for malicious code, secrets, and supply-chain risks before you npm install. 43 checks across 7 layers.

                                      • v0.1.0
                                      • 19.10
                                      • Published

                                      @leochong/npm-scan

                                      Powerful npm supply chain security scanner - detects malicious packages (Shai-Hulud style), behavioral analysis, SBOM, and compliance reporting.

                                      • v0.1.0
                                      • 19.10
                                      • Published

                                      @0xtoxsec/slopcheck

                                      Detect AI-hallucinated packages before you install them.

                                      • v0.6.6
                                      • 19.08
                                      • Published

                                      @kushankurdas/npm-sentinel

                                      Static gate (lockfile + OSV) and isolated Docker npm install with DNS allowlisting

                                      • v0.1.4
                                      • 19.05
                                      • Published

                                      @vibecontrols/vibe-plugin-security-sbom-build

                                      Syft + Grype provider for the build lifecycle stage. Generates a CycloneDX SBOM and scans it for known vulnerabilities. Registers as a security.sbom provider with @vibecontrols/vibe-plugin-security.

                                      • v2026.528.1
                                      • 18.85
                                      • Published

                                      axios-emergency-scanner

                                      axios & OpenClaw 供应链投毒事件应急审计工具 (2026-03-31)

                                        • v1.5.5
                                        • 18.82
                                        • Published

                                        eudr-api-client

                                        Enterprise-grade Node.js library for the EU Deforestation Regulation (EUDR) TRACES system. It provides seamless integration for submitting, amending, retrieving, and managing Due Diligence Statements (DDS) with support for both V1 and V2 APIs.

                                        • v1.0.22
                                        • 18.75
                                        • Published

                                        scriptinel

                                        Install script firewall for npm - default-deny lifecycle scripts with explicit, reviewable allowlists

                                        • v0.1.2
                                        • 18.65
                                        • Published

                                        @lionad/safe-npx

                                        Safe npx wrapper - lock to latest-1 version with 24h cache

                                          • v0.5.1
                                          • 18.59
                                          • Published

                                          depspector

                                          Dependency Inspector - A security analysis tool for npm packages

                                          • v0.0.15
                                          • 18.47
                                          • Published

                                          oss-health-scan

                                          Scan npm dependencies for abandoned packages, outdated versions (libyear), and known CVEs (OSV.dev). Health scores 0-100, SARIF for GitHub Code Scanning, zero dependencies.

                                          • v1.6.0
                                          • 18.41
                                          • Published

                                          package-age-guard

                                          Block npm packages that are too new - protect against supply chain attacks

                                          • v1.2.0
                                          • 18.37
                                          • Published

                                          @foxom/awilint

                                          Static checks for agentic workflow injection risks in GitHub Actions.

                                          • v0.1.0
                                          • 18.32
                                          • Published

                                          @allenwu06/mcpaudit

                                          Static pre-install security scanner for MCP (Model Context Protocol) servers — `npx mcpaudit <path>` flags command injection, credential/env exfiltration into LLM-visible output, over-broad filesystem/tool scope and dynamic eval before you wire a server i

                                            • v0.1.0
                                            • 18.18
                                            • Published

                                            brin

                                            the credit score for context — security scanning for packages, repos, MCP servers, skills, domains and commits

                                            • v0.1.16
                                            • 18.07
                                            • Published

                                            npm-hardener

                                            Paranoid by default supply chain protection for developers

                                              • v1.0.11
                                              • 18.03
                                              • Published

                                              @cyberhub/trust-recallai-desktop-sdk

                                              Security Trust Report: @recallai/desktop-sdk@2.0.12 — 64/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.2
                                              • 17.91
                                              • Published

                                              @cyberhub/trust-arcadialdev-arcality

                                              Security Trust Report: @arcadialdev/arcality@2.4.36 — 65/100 (B, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.6
                                              • 17.88
                                              • Published

                                              @cyberhub/trust-scopieflows-apps-framework

                                              Security Trust Report: @scopieflows/apps-framework@0.28.3 — 62/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.0
                                              • 17.70
                                              • Published

                                              depmedic

                                              Surgical npm vulnerability triage. Minimum-bump fixes, prod/dev split, transitive depth, no breaking surprises.

                                              • v0.1.4
                                              • 17.67
                                              • Published

                                              @agentdefenders/mcp-scan

                                              MCP supply chain scanner - detect tool poisoning, prompt injection, and shadowing attacks

                                              • v0.5.0-alpha
                                              • 17.65
                                              • Published

                                              skill-lint

                                              Security linter for Claude Code / agent skills. Detects prompt injection, obfuscation, credential exfiltration, and other toxic patterns before you install a skill.

                                              • v0.2.0
                                              • 17.62
                                              • Published

                                              supply-scan

                                              Universal npm supply chain attack scanner. Detects compromised packages from 12+ known attacks.

                                              • v1.1.0
                                              • 17.54
                                              • Published

                                              @cyberhub/trust-nx

                                              Security Trust Report: nx@22.7.1 — 61/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.2
                                              • 17.50
                                              • Published

                                              @cyberhub/trust-scopieflows-apps-common

                                              Security Trust Report: @scopieflows/apps-common@0.12.3 — 60/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.0
                                              • 17.47
                                              • Published

                                              @cyberhub/trust-xml2js

                                              Security Trust Report: xml2js@0.6.2 — 61/100 (C+, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.3
                                              • 17.44
                                              • Published

                                              patchpilots-mcp

                                              PatchPilots security and accessibility agents as an MCP server. Security scanning, supply chain analysis, and WCAG 2.1 AA audits inside Claude Code, Cursor, and any MCP-compatible IDE.

                                              • v0.3.3
                                              • 17.41
                                              • Published

                                              @cyberhub/trust-7365admin1-core

                                              Security Trust Report: @7365admin1/core@2.46.0 — 54/100 (C, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.3
                                              • 17.41
                                              • Published

                                              @foxom/hookseal

                                              Audit npm package-lock install hooks with a small explicit allowlist.

                                              • v0.1.0
                                              • 17.36
                                              • Published

                                              @cyberhub/trust-amit-logger-js

                                              Security Trust Report: amit-logger-js@1.0.2 — 57/100 (C+, standard). Maintainer risk, supply chain analysis from 8 security databases.

                                              • v1.0.2
                                              • 17.33
                                              • Published

                                              @cmdoss/cryptoguard-sdk

                                              CryptoGuard SDK for Chrome extensions and Node.js servers - SLSA Level 3 binary transparency verification

                                              • v1.0.0
                                              • 17.24
                                              • Published

                                              npx-ray

                                              X-ray vision for npm packages — security scanner that audits source code, detects obfuscation, and flags supply chain risks before you install

                                              • v1.0.3
                                              • 17.19
                                              • Published

                                              attestium

                                              Element of attestation - Runtime code verification and integrity monitoring library for Node.js applications

                                              • v0.0.3
                                              • 17.15
                                              • Published

                                              @depchain/cli

                                              Package dependency intelligence - work in progress.

                                              • v0.0.1
                                              • 17.13
                                              • Published