# AikidoSec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

Repository: https://github.com/AikidoSec/safe-chain
Canonical: https://ross.abutalabs.com/products/safe-chain
Homepage: https://www.aikido.dev
Language: JavaScript
License: NOASSERTION
License Family: other
Last push: 2026-08-26T08:59:16+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 96, longevity 29
- inputs: {"age_days": 418, "days_push": 7, "days_rel": 28, "gap_med": 3.5, "n_releases_24m": 53}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1725, forks 110 (observed 2026-08-28T04:05:28.055548+00:00)

## What it is
Aikido Safe Chain is a free, tokenless CLI tool that wraps package managers (npm, yarn, pnpm, npx, pip, uv, poetry, and more) to block malicious packages from being installed on developer machines and CI/CD. It blocks newly published packages (under 48 hours old) that match known malware indicators without breaking builds or sharing build data.

## Use cases
- protect developer laptops from malicious npm packages
- block supply chain attacks in CI/CD pipelines
- prevent installing malware via pip or poetry
- secure npx and uvx package execution
- guard against typosquatting and malicious dependency installs
- add malware scanning to package installation without tokens or accounts

## When to choose
- you want free, tokenless protection against malicious package installs across npm and PyPI ecosystems
- you need to secure both developer workstations and CI/CD runners
- you want a lightweight wrapper around existing package managers rather than a full security platform

## When to avoid
- you need coverage beyond npm and PyPI, such as Maven, NuGet, Go, or Ruby (consider Aikido Device Protection instead)
- you require centralized policy management, approvals, and org-wide visibility
- you need full SCA, SAST, or vulnerability scanning rather than install-time malware blocking

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, dependency-audit, cli, developer-tools
- domain: security, developer-tools
- platform: windows, cli, cross-platform, python
- tags: supply-chain-security, malware-blocking, package-manager-wrapper, npm, pypi, sca, ci-cd-security, free-tool, command-line, automation, linux, macos, nodejs

## Member repositories
- AikidoSec/safe-chain (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:28.055548+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:32:34.139214+00:00, confidence not recorded.
  - readme: https://github.com/AikidoSec/safe-chain (fetched 2026-08-28T04:05:28.055548+00:00, sha c65454ff3779)
  - homepage: https://www.aikido.dev (fetched 2026-08-29T11:09:41.516963+00:00, sha 53719c68e29f)
  - site_page: https://apidocs.aikido.dev/ (fetched 2026-08-29T11:09:41.529513+00:00, sha 24071331ebdd)
  - site_page: https://www.aikido.dev/company/about (fetched 2026-08-29T11:09:41.534773+00:00, sha a6e021bd645f)
  - site_page: https://www.aikido.dev/code/ide-integrations (fetched 2026-08-29T11:09:41.526021+00:00, sha 00e9de08df23)
  - site_page: https://help.aikido.dev (fetched 2026-08-29T11:09:41.527814+00:00, sha 6778d700644e)
  - site_page: https://help.aikido.dev/changelog (fetched 2026-08-29T11:09:41.531317+00:00, sha 11b44cc4e340)
  - site_page: https://integrations.aikido.dev/ (fetched 2026-08-29T11:09:41.533120+00:00, sha 19984bc1a9f7)
  - site_page: https://www.aikido.dev/pricing (fetched 2026-08-29T11:09:41.536349+00:00, sha 2d8ca5da11ab)
- Data as of 2026-08-30T08:39:29.467469+00:00.
