Project overview
This standalone agent skill scans local files, lockfiles, processes, persistence points, containers, and CI surfaces for indicators from documented npm and PyPI worm campaigns. Its key safety rule is to stop persistence and quarantine evidence before revoking credentials, then release a dependency-ordered rotation plan only after a clean second scan. It supports macOS, Linux, Windows, WSL, containers, and CI, but remains an incident-response runbook rather than a guarantee of safety.
Repository facts
- Primary language
- Not detected
- License
- MIT
- Repository updated
- May 13, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Runtime
Local
Capabilities
Verification and evals
Audience
Developers