
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@merchantguard/guardscan
Advanced tools
Security scanner for AI agent skills — 102 patterns, 17 categories, payment/PCI compliance, prompt injection detection. Local by default, no code leaves your machine.
Security scanner for AI agent skills. 99 patterns, 17 categories, payment/PCI compliance, prompt injection detection. Local by default — no code leaves your machine.
npm install @merchantguard/guardscan
# Scan a directory
npx @merchantguard/guardscan .
# Scan specific files
npx @merchantguard/guardscan ./src/index.ts ./lib/auth.ts
# Output SARIF (GitHub Code Scanning, VS Code)
npx @merchantguard/guardscan . --sarif > guardscan.sarif
# Output CLAUDE.md (fix instructions for Claude Code)
npx @merchantguard/guardscan . --claudemd > GUARDSCAN.md
# JSON output
npx @merchantguard/guardscan . --json
| Flag | Description |
|---|---|
--sarif | SARIF 2.1.0 JSON output |
--claudemd | Markdown with fix instructions for Claude Code |
--json | Raw JSON result |
--quiet | Summary only, no finding details |
--help | Show usage |
0 — No critical findings1 — Critical findings detectedimport { scanFiles } from '@merchantguard/guardscan';
const result = scanFiles([
{ name: 'index.ts', content: 'const key = "sk-proj-abc123..."' }
]);
console.log(result.securityScore); // 0-100
console.log(result.status); // 'red' | 'yellow' | 'green'
console.log(result.findings); // ScanFinding[]
scanFiles(files)Scans an array of { name: string, content: string } objects.
Returns a ScanResult:
interface ScanResult {
scanId: string;
status: 'red' | 'yellow' | 'green';
statusLabel: string;
securityScore: number; // 0-100
filesScanned: number;
linesScanned: number;
findings: ScanFinding[];
summary: {
total: number;
critical: number;
high: number;
medium: number;
low: number;
};
paymentContext: PaymentContext;
}
toSarif(result)Converts a ScanResult to SARIF 2.1.0 format for GitHub Code Scanning or VS Code SARIF Viewer.
import { scanFiles, toSarif } from '@merchantguard/guardscan';
const result = scanFiles(files);
const sarif = toSarif(result);
fs.writeFileSync('guardscan.sarif', JSON.stringify(sarif, null, 2));
generateClaudeMd(result)Generates a CLAUDE.md file with fix instructions that Claude Code can follow.
import { scanFiles, generateClaudeMd } from '@merchantguard/guardscan';
const result = scanFiles(files);
fs.writeFileSync('GUARDSCAN.md', generateClaudeMd(result));
Half-life scoring formula: score = 100 * (0.5 ^ (deductions / 80))
| Severity | Deduction |
|---|---|
| CRITICAL | 25 |
| HIGH | 15 |
| MEDIUM | 8 |
| LOW | 3 |
| Score | Status | Label |
|---|---|---|
| 90-100 | green | Safe |
| 70-89 | yellow | Caution |
| 40-69 | yellow | Risky |
| 0-39 | red | Dangerous |
secrets, auth, xss, injection, config, rate-limit, pci-dss, compliance, crypto, file, malware, prompt-injection, data-exfil, tool-abuse, autonomy-abuse, skill-manifest, obfuscation
GuardScan detects payment provider usage (Stripe, Adyen, Braintree, PayPal, Square, Authorize.net, Worldpay, Checkout.com, Klarna, Affirm, Plaid, Marqeta) and flags PCI-DSS relevant findings.
Try GuardScan online at merchantguard.ai/guardscan
MIT
FAQs
Security scanner for AI agent skills — 102 patterns, 17 categories, payment/PCI compliance, prompt injection detection. Local by default, no code leaves your machine.
The npm package @merchantguard/guardscan receives a total of 0 weekly downloads. As such, @merchantguard/guardscan popularity was classified as not popular.
We found that @merchantguard/guardscan demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.