JustHandled Labs
// security

Package Supply-Chain Sentinel

Vet dependency changes for supply-chain risk before you install, commit, or release.

What it does

Scans package and lockfile diffs for install-time lifecycle scripts, non-registry sources, suspicious download commands, typosquatting, and floating versions, across npm, pnpm, yarn, pip, uv, and poetry. Flags what to review with evidence.

How to run

Get it on Agensi and run it with any agent that reads SKILL.md, such as Claude Code, Codex, or Cursor. The listing includes setup steps and exactly what it reads.

Good to know

No install required.

Questions

What does Package Supply-Chain Sentinel do?

Vet dependency changes for supply-chain risk before you install, commit, or release.

What does it need to run?

No install required.

Add Package Supply-Chain Sentinel to your toolkit.

Current price and purchase option are shown on Agensi. Instant download. Works with any agent that reads SKILL.md.

Get Package Supply-Chain Sentinel on Agensi