
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
shebang-sherpa-mcp
Advanced tools
Aggregate local script portability risks without exposing script text or project names. Tools include inspect script portability
Shebang Sherpa is a local portability audit for scripts that work on one laptop and mysteriously fail on another. It scans bounded script candidates and reports aggregate interpreter categories, executable-bit coverage, and coarse portability warnings.
inspect_script_portability: scan a local project without executing scripts.The result can flag machine-specific interpreter paths, legacy interpreter names, absolute system interpreters, executable files without shebangs, and scripts missing the executable bit. It never returns paths, script text, project names, dependency names, command arguments, or environment values.
SHEBANG_SHERPA_ROOT.npm install
npm run build
node dist/index.js
npm install
npm run build
node dist/index.js
The server uses stdio, so it can be connected to Claude Desktop, Cursor, VS Code, MCP Inspector, or another compatible MCP client.
inspect_script_portability: Aggregate local script interpreter and launcher portability signals without returning paths, script text, project names, dependency names, or command arguments.After building, connect the server through your MCP client. The repository root also contains smoke-test.mjs for projects covered by the shared harness. A typical tool call starts with inspect_script_portability.
FAQs
Aggregate local script portability risks without exposing script text or project names. Tools include inspect script portability
We found that shebang-sherpa-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.