What it does
A pre-install security gate that uses Jev to inspect npm lifecycle scripts before they run.
Apps & data pipelines
Only you can see your notes.
Screenshot unavailable. Open the experiment ↗
A pre-install security gate that uses Jev to inspect npm lifecycle scripts before they run.
A developer can adapt this code to check software packages before installing them. The tool extracts hidden installation scripts and sends them to an outside AI service called TypeSafe. You need an access key from TypeSafe to connect the software. Without a key, the tool uses an offline simulator instead.
The service returns a decision to allow, warn, or block the package. It blocks commands marked dangerous, but this does not guarantee complete safety. If the system is uncertain, it waits for a person to decide. Keep in mind that your raw scripts are sent over the internet to TypeSafe.