Skip to main content
SafeDep protects developers and AI coding agents against malicious open source components. You can inspect the code you write. You cannot inspect everything you depend on: packages, IDE extensions, Agent Skills, MCP servers, and GitHub repositories. Every one of them can carry a supply chain attack, and campaigns like Shai-Hulud, Miasma, and S1ngularity spread exactly this way. SafeDep closes this blindspot. It blocks malicious components before their code runs, and it gives you visibility and policy over everything else you depend on. Its core tools (Vet, PMG, xBom, and Gryph) are free, open source, and usable without a SafeDep account. SafeDep Cloud adds hosted policy, inventory, and org-wide visibility when your team is ready. New here? Choose your path: start free with one tool, add Cloud when your team is ready.

Where to start

Block malicious packages

Stop malicious and vulnerable packages at install time and in CI/CD, with PMG and Vet.

Secure AI coding agents

Discover, audit, and control what AI agents access and run, with Gryph and the MCP server.

Scan & govern dependencies

Scan repositories, SBOMs, and CI/CD for risk, and govern policy across your org with Vet and SafeDep Cloud.

How SafeDep works

Understand how SafeDep detects malicious packages, plus the core terms used across these docs.