
Product
Socket MCP Adds Org Alerts, Threat Feed Review, and Package Inspection
Socket MCP now lets AI assistants review org alerts, investigate threats using the Socket threat feed, and inspect package files in addition to dependency scoring.
@filepad/guardian
Advanced tools
Filepad Guardian — local evidence reporter for Active Contracts. Runs checks, captures provenance, reports evidence to Filepad.
Filepad Guardian is the local repo-runtime verifier for Active Contracts.
It runs inside an explicit external execution target, such as an agent's local repository, a CI checkout, or a sandbox checkout. It does not belong in the Filepad product backend.
npm install -g @filepad/guardian
or run it without a global install:
npx -y @filepad/guardian@latest --help
Guardian reports evidence through Agent Access credentials:
export FILEPAD_BASE_URL=https://api.filepad.ai
export FILEPAD_WORKSPACE_ID=ws_...
export FILEPAD_AGENT_KEY_ID=ik_...
export FILEPAD_AGENT_SECRET=...
The credentials must be issued for the workspace and execution target that the agent is working against. Generic MCP agents should not self-declare trusted Guardian evidence.
filepad-guardian status
filepad-guardian contract status --contract-id ac_...
filepad-guardian run --contract-id ac_... --check-id backend_typecheck
filepad-guardian run --contract-id ac_... --check-id backend_tests -- pnpm test
filepad-guardian report --contract-id ac_... --json evidence.json
filepad-guardian soundness --contract-id ac_... --repo-root .
filepad-guardian watch --contract-id ac_... --repo-root . --rerun manual
Guardian owns repo-runtime work:
Filepad owns the coordination plane:
The Filepad backend must not import Guardian or use its own runtime filesystem as a customer repository.
Before publishing, this package must pass:
pnpm -C packages/guardian typecheck
pnpm -C packages/guardian test
pnpm -C packages/guardian pack:check
The test suite includes an empty-project install smoke test. It packs Guardian,
installs the tarball into a temporary project, and verifies that the
filepad-guardian binary runs from node_modules/.bin.
FAQs
Filepad Guardian — local evidence reporter for Active Contracts. Runs checks, captures provenance, reports evidence to Filepad.
We found that @filepad/guardian demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket MCP now lets AI assistants review org alerts, investigate threats using the Socket threat feed, and inspect package files in addition to dependency scoring.

Product
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.

Research
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.