
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
agentguard-burn
Advanced tools
AgentGuard Burn: see where your Claude Code and Codex tokens went, and stop runaway sub-agents. Runs locally; nothing is uploaded. Short name for @agentguard-run/burn.
The short name for AgentGuard Burn (@agentguard-run/burn).
npx agentguard-burn why
why shows where one Claude Code or Codex session's tokens went: sub-agent fan-out, history re-sent, cache rewrites and the rest, with API list-price equivalents. Every dollar figure is a list-price equivalent, not a bill. It reads the usage your host already saved on your machine; nothing is uploaded.
Every Burn command works the same way through this name, for example npx agentguard-burn rewrites or npx agentguard-burn resume --once --reason "...". The report prints in Latin American Spanish or Brazilian Portuguese when your computer is set to those languages, or with --lang es or --lang pt.
This package contains only a launcher. It installs @agentguard-run/burn and runs it with your arguments. Full documentation: https://agentguard.run/burn
AgentGuard is a registered trademark of Dunecrest Ventures Inc.
FAQs
AgentGuard Burn: see where your Claude Code and Codex tokens went, and stop runaway sub-agents. Runs locally; nothing is uploaded. Short name for @agentguard-run/burn.
The npm package agentguard-burn receives a total of 173 weekly downloads. As such, agentguard-burn popularity was classified as not popular.
We found that agentguard-burn demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.