$npx skillfedfor your agent

ca9

Open source Python package security and evidence-backed SCA triage

With conditionsPyPI SecurityReleased Jun 202677.3K downloads / moMPL-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — ca9-0.5.0-py3-none-any.whl
v0.5.0 · released 2026-06-27 · Python >=3.10 · 2 runtime deps: packaging, tomli

Yes, if you use Python and want to reduce CVE alert noise with evidence-backed triage. ca9 is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—most flagged CVEs are unreachable. The MPL-2.0 license is permissive for local use. Start with `ca9 scan` on an existing SCA report to see the impact. Early-stage (Alpha), so expect API evolution, but the core reachability logic is sound.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • For full functionality, your project should have a recognized lockfile or SCA report to analyze.
  • Low friction: pure Python wheel with only two runtime dependencies (packaging, tomli).

License · maintenance · safety

MPL-2.0 (copyleft) — MPL-2.0 is copyleft: you may use ca9 freely and modify it, but if you distribute modified versions, you must disclose source and license derivative works under MPL-2.0. For most local security tooling use, this poses no practical barrier.

last release 2026-06-27 (48 days) · last repo commit 2026-08-14 · 8 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,301 downloads/mo, #14,537 on PyPI

Verify before relying

pip install ca9[cli]
ca9 scan --repo . --coverage coverage.json
ca9 inventory --repo . -f json
  • Whether static import tracing and coverage analysis work reliably on complex dependency graphs with dynamic imports.
  • Performance characteristics on large monorepos or projects with hundreds of transitive dependencies.
  • Completeness of vulnerable API detection rules and how often they require manual tuning.
  • Reliability of reachability verdicts across different Python packaging patterns and import styles.
Same gist for agents: .md · .json

What it is and what it does

ca9 is a local-first supply-chain defense tool that reads your Python project's manifests, lockfiles, and SCA reports, then answers a single critical question for each CVE alert: is this vulnerable code actually reachable from your application? It combines three evidence sources—static AST import tracing, dependency graph analysis, and optional runtime coverage data—to classify each vulnerability as reachable, unreachable (static or dynamic), or inconclusive, with an evidence trail and confidence score for each verdict.

Instead of patching every flagged CVE, you get a filtered list of only the vulnerabilities that matter: code your app actually imports and executes. ca9 also provides broader supply-chain vetting (malware advisories, registry trust, artifact hashes, license policy, dependency confusion risk) and runtime preflight enforcement via `ca9 run`, so you can block unsafe packages before they install. It reads native Python manifests, npm lockfiles, and SBOM inputs, and outputs JSON, SARIF, OpenVEX, or Markdown for integration into CI gates and audit workflows.

Use it for

  • Filter CVE alerts from SCA tools to identify which vulnerabilities actually affect your code, reducing alert fatigue.
  • Build a normalized package inventory from mixed lockfile formats to audit direct and transitive dependencies.
  • Enforce supply-chain policy in CI by blocking untrusted registries, dependency-confusion risks, or missing hashes.
  • Combine static import analysis with coverage data to confirm whether a vulnerable function is ever called.
  • Generate OpenVEX or SARIF reports for downstream security tools, enriching SCA output with reachability evidence.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you use Python and want to reduce CVE alert noise with evidence-backed triage.

ca9 is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—most flagged CVEs are unreachable. The MPL-2.0 license is permissive for local use. Start with `ca9 scan` on an existing SCA report to see the impact. Early-stage (Alpha), so expect API evolution, but the core reachability logic is sound.

Install

ca9 on PyPI

Before you install

Low friction: pure Python wheel with only two runtime dependencies (packaging, tomli). Active maintenance—last commit 2026-08-14, released 2026-06-27, only 48 days old. Supports Python 3.10 through 3.13. No known vulnerabilities.

Requires Python 3.10 or later. For full functionality, your project should have a recognized lockfile or SCA report to analyze.

License in practice

MPL-2.0 is copyleft: you may use ca9 freely and modify it, but if you distribute modified versions, you must disclose source and license derivative works under MPL-2.0. For most local security tooling use, this poses no practical barrier.

Quickstart

pip install ca9[cli]
ca9 scan --repo . --coverage coverage.json
ca9 inventory --repo . -f json

Verify before relying

  • Whether static import tracing and coverage analysis work reliably on complex dependency graphs with dynamic imports.
  • Performance characteristics on large monorepos or projects with hundreds of transitive dependencies.
  • Completeness of vulnerable API detection rules and how often they require manual tuning.
  • Reliability of reachability verdicts across different Python packaging patterns and import styles.

Package facts

LicenseMPL-2.0 copyleft
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
packagingtomli
MaintenanceActively maintained 48 days since the last release
Last repo commit
First released
Downloads77,301 / month, #14,537 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: SecurityTopic :: Software Development :: Quality Assurance

Evidence: ca9-0.5.0-py3-none-any.whl

Tags

Capabilities
cve reachability analysissupply chain security pythonvulnerability triage automationsca report filteringpackage dependency vettingstatic import analysisopen source risk assessment
Topics
supply-chain-securitycve-triagereachability-analysis
PyPI keywords
cvedependabotopenvexosvpip-auditpython-securityreachabilityreachability-analysissarifscasecuritysnyksupply-chain-securitytrivyvulnerability

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cve reachability analysis”

  • ca9ca9 analyzes Python package supply chains to determine whether…
  • debsecan-mcpAn MCP server that scans Debian systems for known security…
  • cwe2cwe2 provides programmatic access to the Common Weakness Enumeration…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also socketsecurity · safety · pip-audit · pysentry-rs · guarddog · pdfid · debsecan-mcp · flawfinder · cvss · hello-world