01Dependency scanning with lockfile ingestion (9 formats) and SBOM export (CycloneDX, SPDX)
02Comprehensive security analysis (OSV, CISA KEV, EPSS, malicious package flags, typosquat detection)
03Covers 19 package ecosystems (e.g., npm, PyPI, Cargo, Go, JSR, Julia)
04Real-time malicious package stream and a Hallucination Benchmark for AI agents
05LLM-optimized API responses for ~74% token reduction in model contexts
061 GitHub stars