Automatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or package manager operation.
Key Features
Automatically gates package installations against known vulnerabilities
Supports multiple package managers including npm, pip, yarn, pnpm, and clawhub
Provides a trust score and detailed findings for packages
Allows agents to contribute new audit data for unknown packages
Enforces security through cooperative, instruction-based agent behavior
Offers cross-platform compatibility with Node.js or Unix-based bash scripts
Facilitates safe download of package source for static analysis without execution
Privacy & Security
Data Collection
This tool follows industry-standard security practices and only collects data necessary for functionality.