JSPM

Found 1210 results for supply-chain

toolprint

package-lock.json for MCP trust — scan MCP servers for tool poisoning, secret leaks, and silent tool rug-pulls, with a committed, reviewable lockfile.

  • v0.1.1
  • 0.00
  • Published

@permanentlymobile/pm-aid

PM AID -- AI agent defense scanner. 73 JS-native modules across prompt injection, secret exposure, supply chain, OSINT, vault hardening, and the AI-agent-runtime surface. Self-hosted. Offline-verified license. One-time ownership.

  • v1.0.2
  • 0.00
  • Published

polin-rider-scanner

Read-only PolinRider / Glassworm supply-chain malware (IOC) scanner — use as a library in CI/pipelines or as a CLI to scan local files and folders

  • v1.0.0
  • 0.00
  • Published

patchdrill

A deterministic proof layer for verifying AI-generated and human patches before merge.

  • v0.1.3
  • 0.00
  • Published

saferskills

Install AI-agent Skills & MCP servers with a verified, independent SaferSkills trust score — across Claude Code, Cursor, Windsurf, Copilot, Codex, Gemini, Cline & OpenClaw.

  • v0.1.1
  • 0.00
  • Published

@marshell/chifu

Make your AI coding agent dependency-security aware. Checks your project's dependencies against known CVEs so your agent can fix what it introduced — before merge.

  • v0.1.6
  • 0.00
  • Published

polin-guard

Block obfuscated build/commit-time code-injection payloads (hidden long-line JS stagers) before they enter your repo. Zero dependencies. Works as a pre-commit hook, in CI, or standalone.

  • v0.3.0
  • 0.00
  • Published

depwarden

Anonymous, zero-account, zero-dependency software composition analysis for CI — vulnerabilities, supply-chain/typosquat, licenses & malware. Never uploads your source.

  • v1.0.0
  • 0.00
  • Published

@webpro/pnpm-exclude-newer

Resolve a pnpm lockfile whose entire dependency tree (direct + transitive) excludes versions published after a cutoff — a transitive minimumReleaseAge / uv-style --exclude-newer for pnpm.

  • v1.0.0
  • 0.00
  • Published