I built an AI-agent skill to audit supply-chain attack exposure
Dependabot already does this without the AI agent overhead.
Package Quarantine and Urgent Release Protocol (PQURP)
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
Package registry maintainers, security engineers
Sigstore · SLSA · npm audit
Dependabot already does this without the AI agent overhead.
Behavioral malware scanning before install, unlike pip-audit.
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.
Forensic triage CLI with verdict system for axios IOC detection.
Maps hidden monopolies like Soitec wafers and Ajinomoto dielectric films.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.