mickdownunder/safeinstall
Check npm packages and install dependencies through SafeInstall's artifact-bound policy gate.
Check an npm package or proposed dependency with the existing SafeInstall engine before recommending or installing it. Use for release-age, install-script, provenance, typo-squat and package-policy questions. A check is not authorization to execute registry code.
Install or add requested npm or pnpm dependencies through SafeInstall's existing artifact-bound installation gate. Use when a user requests dependency installation, including development dependencies. Never use for arbitrary registry-code execution or to bypass a policy block.
Set up the existing SafeInstall policy and trust baseline in a local npm or pnpm project, or help a user enable the SafeInstall plugin hook. Use for SafeInstall onboarding and protection setup, not unrelated package installations.
Inspect an existing SafeInstall project's policy and trust-surface status without changes. Use for protection status, configuration drift, minimum CLI version and whether SafeInstall has been set up. Do not equate a matching trust baseline with active host hook enforcement.