
Agentic Workflows for Malicious Package Analysis
Experiments with agentic workflows for malicious package analysis built using Claude Desktop, Model Context Protocol (MCP) server, static code analysis and SafeDep Cloud API tools.
Follow for the latest updates and insights on
open source security & engineering.

Experiments with agentic workflows for malicious package analysis built using Claude Desktop, Model Context Protocol (MCP) server, static code analysis and SafeDep Cloud API tools.

Introducing vetpkg.dev - Built using SafeDep API to provide an easy to use visibility of open source component security information.

Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.

SafeDep Code Analysis framework augments vet, our free and open source tool with code context.

Start free with open source tools on your machine. Scale to a unified platform for your organization.
