Lateos/NPM-scan – open-source NPM supply chain scanner, v0.18.3
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Behavioral security monitoring for JVM dependencies. Catches malicious package updates before CVEs exist
Catches malicious dependency updates before CVEs exist, unlike Snyk or Dependabot.
Java developers and DevSecOps teams using Maven
Snyk · Dependabot · Socket
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.
Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.
Dependabot alternative with AI test generation and supply chain poisoning checks.
Behavioral malware scanning before install, unlike pip-audit.
Compelling security necropsy undermined by unverifiable claims and speculative narrative.