check_malicious
Verify package safety against OpenSSF/OSV malware database. Use before installing an unfamiliar package from 17 ecosystems to detect known malicious packages and avoid supply-chain attacks.
Instructions
Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ecosystem | Yes | ||
| package | Yes |