Dependency Provenance Gate
RUNTIMES LOADING
Trace names before install.
Compare AI-suggested dependencies with evidence already present in a trusted npm lock snapshot. Similar is a review signal, never an automatic substitute.
Local only. No registry lookup, malware scan, or safety guarantee. A trusted lockfile is evidence supplied by you; near-name matches require human review.
Load the bundled sample or paste two JSON records to trace each proposal.
No dependency trace yet
Exact matches are the only entries allowed into the generated install script.
# verified-install.sh will appear here