New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@merchantguard/guardscan

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@merchantguard/guardscan

Security scanner for AI agent skills — 102 patterns, 17 categories, payment/PCI compliance, prompt injection detection. Local by default, no code leaves your machine.

latest
Source
npmnpm
Version
1.0.0
Version published
Weekly downloads
1
Maintainers
1
Weekly downloads
 
Created
Source

@merchantguard/guardscan

Security scanner for AI agent skills. 99 patterns, 17 categories, payment/PCI compliance, prompt injection detection. Local by default — no code leaves your machine.

Install

npm install @merchantguard/guardscan

CLI

# Scan a directory
npx @merchantguard/guardscan .

# Scan specific files
npx @merchantguard/guardscan ./src/index.ts ./lib/auth.ts

# Output SARIF (GitHub Code Scanning, VS Code)
npx @merchantguard/guardscan . --sarif > guardscan.sarif

# Output CLAUDE.md (fix instructions for Claude Code)
npx @merchantguard/guardscan . --claudemd > GUARDSCAN.md

# JSON output
npx @merchantguard/guardscan . --json

CLI Options

FlagDescription
--sarifSARIF 2.1.0 JSON output
--claudemdMarkdown with fix instructions for Claude Code
--jsonRaw JSON result
--quietSummary only, no finding details
--helpShow usage

Exit Codes

  • 0 — No critical findings
  • 1 — Critical findings detected

Library

import { scanFiles } from '@merchantguard/guardscan';

const result = scanFiles([
  { name: 'index.ts', content: 'const key = "sk-proj-abc123..."' }
]);

console.log(result.securityScore); // 0-100
console.log(result.status);        // 'red' | 'yellow' | 'green'
console.log(result.findings);      // ScanFinding[]

scanFiles(files)

Scans an array of { name: string, content: string } objects.

Returns a ScanResult:

interface ScanResult {
  scanId: string;
  status: 'red' | 'yellow' | 'green';
  statusLabel: string;
  securityScore: number;        // 0-100
  filesScanned: number;
  linesScanned: number;
  findings: ScanFinding[];
  summary: {
    total: number;
    critical: number;
    high: number;
    medium: number;
    low: number;
  };
  paymentContext: PaymentContext;
}

toSarif(result)

Converts a ScanResult to SARIF 2.1.0 format for GitHub Code Scanning or VS Code SARIF Viewer.

import { scanFiles, toSarif } from '@merchantguard/guardscan';

const result = scanFiles(files);
const sarif = toSarif(result);
fs.writeFileSync('guardscan.sarif', JSON.stringify(sarif, null, 2));

generateClaudeMd(result)

Generates a CLAUDE.md file with fix instructions that Claude Code can follow.

import { scanFiles, generateClaudeMd } from '@merchantguard/guardscan';

const result = scanFiles(files);
fs.writeFileSync('GUARDSCAN.md', generateClaudeMd(result));

Scoring

Half-life scoring formula: score = 100 * (0.5 ^ (deductions / 80))

SeverityDeduction
CRITICAL25
HIGH15
MEDIUM8
LOW3
ScoreStatusLabel
90-100greenSafe
70-89yellowCaution
40-69yellowRisky
0-39redDangerous

17 Categories

secrets, auth, xss, injection, config, rate-limit, pci-dss, compliance, crypto, file, malware, prompt-injection, data-exfil, tool-abuse, autonomy-abuse, skill-manifest, obfuscation

Payment Context

GuardScan detects payment provider usage (Stripe, Adyen, Braintree, PayPal, Square, Authorize.net, Worldpay, Checkout.com, Klarna, Affirm, Plaid, Marqeta) and flags PCI-DSS relevant findings.

Web UI

Try GuardScan online at merchantguard.ai/guardscan

License

MIT

Keywords

security

FAQs

Package last updated on 07 Feb 2026

Related posts