
LLM-assisted supply chain diff analyzer for detecting malicious npm/PyPI package updates. Combines semantic diff analysis (Claude) with threat intelligence feeds (OSV, Rekor/Sigstore, OpenSSF Scorecard, and a new-dependency provenance heuristic) and a ground-truth corpus of real, independently-sourced-and-verified malicious package incidents. Reports record per-stage timings and explicit caveats about evidence the LLM did not see; a --strip-comments control isolates how much of a score comes from prose rather than code.
