
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@skarn-security/skarn
Advanced tools
Skarn - AI coding session security scanner. Single static binary; this launcher resolves and runs the prebuilt binary for your platform (no download at install time).
AI coding session security scanner with built-in session search. This package is a thin launcher: it selects the prebuilt binary for your platform (shipped as optional dependencies) and forwards all arguments and exit codes to it.
Run without installing:
npx @skarn-security/skarn assess
Or install globally:
npm install -g @skarn-security/skarn
skarn assess
With the global install on your PATH, Cursor and VS Code register the MCP server with one click; both buttons run skarn mcp:
The version-pinned npx buttons, which need only Node, are on https://getskarn.com/install/?utm_source=npm-readme&utm_medium=referral&utm_campaign=install&utm_content=mcp
skarn assess needs no license. skarn check scans need one - the free license is instant: https://getskarn.com/free?utm_source=npm-readme&utm_medium=referral&utm_campaign=free&utm_content=license
Skarn is licensed under the Skarn End User License Agreement, distributed with this package as EULA.md and published at https://getskarn.com/terms/?utm_source=npm-readme&utm_medium=referral&utm_campaign=terms&utm_content=eula. Skarn asks for your acceptance the first time you run it; running it constitutes acceptance.
Documentation: https://getskarn.com/manual/?utm_source=npm-readme&utm_medium=referral&utm_campaign=docs&utm_content=manual
FAQs
Skarn - AI coding session security scanner. Single static binary; this launcher resolves and runs the prebuilt binary for your platform (no download at install time).
The npm package @skarn-security/skarn receives a total of 71 weekly downloads. As such, @skarn-security/skarn popularity was classified as not popular.
We found that @skarn-security/skarn demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.