
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@stlw/warden
Advanced tools
@stlw/warden is a deterministic, fail-closed authorization runtime for AI agent actions.
npm install @stlw/warden
import { createWarden, definePolicy } from "@stlw/warden";
const warden = createWarden();
const decision = await warden.evaluate(
definePolicy({ id: "allow-read", version: 1, rules: [{ id: "allow", effect: "ALLOW" }] }),
{ subject: { id: "agent-1" }, action: "read", resource: { id: "doc-1" } },
);
Unmatched rules and evaluation errors deny by default. See the Warden repository for full documentation.
FAQs
Deterministic policy engine for autonomous agent tool enforcement
The npm package @stlw/warden receives a total of 430 weekly downloads. As such, @stlw/warden popularity was classified as not popular.
We found that @stlw/warden demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.