Pytest tests catching Python supply chain attacks (litellm .pth vector)
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.
Pre-install malware guard for Python packages, plus blast-radius containment for agent workflows
Behavioral malware scanning before install, unlike pip-audit.
Python developers and security-conscious teams
pip-audit · safety · OSV-Scanner
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.
First real supply-chain defense for AI agent ecosystems; catches nation-state-grade payloads.
Forensic triage CLI with verdict system for axios IOC detection.
Yet another Python installer, but pyenv and Docker already do this better.