Hybrid AI agent that scans project dependencies for supply-chain risk. Hardened against the Mini Shai-Hulud / TeamPCP worm campaign (May 2026) — self-propagating malware in npm/PyPI/VS Code extensions that hides in postinstall scripts and harvests credentials. Combines deterministic checks (typosqua
Publisher has not attached a README.
Unsigned — install will be refused at workspace boot.
No published versions yet.