The pipeline behind every advisory you see in the feed. Built and operated by a single research team. Open-sourced where possible.
Every new release on npm, Docker Hub, GHCR, the MCP registry, and Hugging Face is mirrored into a content-addressed store within minutes of publication.
Tarballs and OCI layers are unpacked, normalized, and fed through ASTs, opcode analyzers, and pickle/safetensor walkers to surface obfuscation, network sinks, and serialization sinks.
Suspicious artifacts are detonated inside ephemeral microVMs with full syscall, DNS, and filesystem tracing. We diff observed behavior against a learned baseline per ecosystem.
Researchers reproduce the finding, score it under CVSS 3.1, write a minimal PoC, and confirm the affected version range against upstream tags.
Maintainer is notified with a 90-day clock. Embargo is lifted on patch release or expiry, whichever comes first. Advisory ships with patch diff and detection rules.