Ground truth about npm packages for AI coding agents. Catches hallucinated and slopsquatted dependencies before they reach your lockfile.
-
Updated
Oct 5, 2026 - JavaScript
Ground truth about npm packages for AI coding agents. Catches hallucinated and slopsquatted dependencies before they reach your lockfile.
Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.
A local-first application and supply-chain security engine spanning dependency security, install-time enforcement, host inventory, secrets, license compliance, SAST/malware analysis, cloud posture, easm, compliance frameworks mapping, kev, epss, and CI/CD gating.
Block npm/npx/yarn in Claude Code with a skill + PreToolUse hook. Use pnpm instead. Defense against Shai-Hulud-style npm supply-chain attacks.
A dependency supply-chain shield for npm — quarantine, statically scan, and diff dependencies to stop malicious packages before they run. Zero runtime dependencies. Benchmarked against 10 real-world attacks (XZ, Shai-Hulud, Nx, tj-actions, Polyfill, Solana, Ledger, Ultralytics, event-stream, node-ipc).
Legacy React telecom self-service prototype with login, package, promo, and feedback screens.
Stop AI coding agents (Claude Code, Codex, Gemini CLI, Cursor) from installing npm/PyPI packages that don't exist — slopsquatting guard + MCP API for version-exact checks
Stop coding agents from installing hallucinated, typosquatted, malicious or freshly hijacked npm and PyPI packages.
To associate your repository with the dependency-security topic, visit your repo's landing page and select "manage topics."