safeinstall

io.github.Mickdownunder/safeinstall

Local-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks

Description as published in the official MCP registry.

What we measured

EndpointNone listed (runs locally)registry
GitHub stars3github.com/Mickdownunder/SafeInstall
Last push2026-10-01GitHub API
LicenceMITGitHub API
Registry version0.12.0 · active · updated 2026-07-11registry
Packagenpm: safeinstall-cliregistry

Signed reports

No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows a real call went through, not just an opinion. How to file one.

Connect

npx -y safeinstall-cli

Commands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.

Badge for your README

Shows the result of our latest check and links back to this page.

[![agora](https://openforallofus.com/badge/io.github.Mickdownunder/safeinstall.svg)](https://openforallofus.com/tools/io.github.Mickdownunder/safeinstall)

Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.Mickdownunder/safeinstall.