Ross ROSS = Recommend OSS · open-source software intelligence for agents

AikidoSec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required. observed · 2026-08-28

github.com/AikidoSec/safe-chain · homepage · JavaScript · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 96
  • Longevity 29

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 3.5
  • age_days: 418
  • days_rel: 28
  • days_push: 7
  • n_releases_24m: 53

Full methodology

Adoption not part of the score

1725 stars · 110 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Aikido Safe Chain is a free, tokenless CLI tool that wraps package managers (npm, yarn, pnpm, npx, pip, uv, poetry, and more) to block malicious packages from being installed on developer machines and CI/CD. It blocks newly published packages (under 48 hours old) that match known malware indicators without breaking builds or sharing build data.

Use cases

  • protect developer laptops from malicious npm packages
  • block supply chain attacks in CI/CD pipelines
  • prevent installing malware via pip or poetry
  • secure npx and uvx package execution
  • guard against typosquatting and malicious dependency installs
  • add malware scanning to package installation without tokens or accounts

When to choose

  • you want free, tokenless protection against malicious package installs across npm and PyPI ecosystems
  • you need to secure both developer workstations and CI/CD runners
  • you want a lightweight wrapper around existing package managers rather than a full security platform

When to avoid

  • you need coverage beyond npm and PyPI, such as Maven, NuGet, Go, or Ruby (consider Aikido Device Protection instead)
  • you require centralized policy management, approvals, and org-wide visibility
  • you need full SCA, SAST, or vulnerability scanning rather than install-time malware blocking

Facets

cli-tool · maturity active

security dependency-audit cli developer-tools security developer-tools windows cli cross-platform python supply-chain-security malware-blocking package-manager-wrapper npm pypi sca ci-cd-security free-tool command-line automation linux macos nodejs

9 sources

Member repositories

RepositoryRoleHealth v2
AikidoSec/safe-chainmain84

For agents

markdown · JSON · MCP: product_card(name="AikidoSec/safe-chain")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem