nowfound

Alternatives

Products that do what Pipguard does

Pre-install malware guard for Python packages

  1. 1

    The AI-Powered Antivirus for AI Agents

    Mar 2026 · clawsecure.ai

  2. 2PS

    Pipask is a drop-in replacement for pip that addresses a serious security flaw: standard pip executes arbitrary code from source distributions during dependency resolution, without warning or consent. Pipask retrieves metadata through PyPI's JSON API first, then checks repository popularity, download counts, package age, and known vulnerabilities before allowing installation. It presents you with a pretty report and asks for you consent with installation, giving you control over what code runs on your system. More details in the intro blog post:…

    2025 · github.com

  3. 3
    Warestack444

    Agentic guardrails for safe releases

    2025

  4. 4

    The AI-Powered Antivirus for AI Agents

    May 2026 · clawsecure.ai

  5. 5
    Refuse84

    Block vulnerable package installs for you and your AI

    Jun 2026 · refuse.dev

  6. 6

    Protect your LLM applications with a few lines of code.

    2023

  7. 7MA

    Hi HN! We are excited to show you modguard - a Python tool we built to enforce a modular, decoupled package architecture. We built modguard to solve a recurring problem that we've experienced on software teams - code sprawl. Over time, cross-module imports would tightly couple together what used to be independent domains, and eventually create "balls of mud". This made it harder to test, and harder to make changes. Mis-use of modules which were intended to be private would then degrade performance and even cause security incidents. This would happen for a variety of reasons: - Junior…

    2024 · github.com

  8. 8NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  9. 9
    noirdoc96

    PII guard for Claude Code to keep client data out of context

    Apr 2026 · noirdoc.de

  10. 10

    Stop AI agents from installing malicious packages.

    Jul 2026 · agentinel.habitwala.in

  11. 11AC
  12. 12DO

    I kept seeing every npm/pnpm/yarn/bun/uv supply chain post end with the same advice (set a minimum release age, turn off install scripts), and while I know cooldowns are "controversial", they do work. But even if you convince people that they should set cooldowns, it seems many don't end up following through, not sure why, maybe because it means hand-editing five config files in five formats with five different time units, or perhaps the "it won't happen to me" syndrome (or "I'll do it later, it seems complicated" where it's actually very simple). So I created a tool that…

    Jun 2026 · github.com

  13. 13

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  14. 14FL

    Hi HN! We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated. We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40%…

    2025

  15. 15

    Scans AI agent skills for malicious code

    11d ago · github.com

  16. 16

    A pre-execution guard that stops your coding agent running destructive commands. One shell file, no dependencies. - vandith1/agent-guard

    22d ago · github.com

  17. 17

    7 layers between your AI agents and disaster.

    Feb 2026 · takeinterest.ai

  18. 18

    Selfhosted proxy; scrubs secrets from AI Agent tool calls.

    Mar 2026 · quiguardweb.vercel.app

  19. 19

    AI-powered code review, right in your commits.

    Jan 2026 · commitguard.ai

  20. 20HT

    I recently began using Python for AI projects and found Rye, which is an all-in-one tool that replaces Pyenv, Pip, and Venv, for a more project-centered approach to Python development (like Ruby or JavaScript or Rust). As someone who habitually writes tutorials for beginners, I wrote a series of articles for my mac.install.guide site advocating setting up Python projects using Rye. Am I leading beginners down the wrong path by suggesting Rye for Python tooling? Beginners often encounter READMEs and tutorials that show `pip install something` as a first step. That led me to the error "Command…

    2024

  21. 21DG
  22. 22

    Local security & compliance scanner for AI agents

    Jul 2026 · safeclaude.net

  23. 23IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  24. 24

    Control AI-generated code before it ships.

    Apr 2026 · guardianide.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →