guarddog
GuardDog is a CLI tool for identifying malicious open source packages
Decision gist · record as of 2026-08-14
Yes. GuardDog is actively maintained, has no known vulnerabilities, and fills a specific gap in supply chain security by correlating code capabilities with threat indicators rather than generating false-positive noise. The sandboxed scanning protects against execution during analysis. Install it if you need to audit dependencies across multiple package ecosystems or integrate package security checks into CI/CD; skip it if you only use a single ecosystem and already have ecosystem-specific tooling.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10+.
- Sandboxed scanning (default) requires Linux Landlock or macOS Seatbelt; use --no-sandbox to disable.
- Windows requires Docker.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for integration into security workflows and CI/CD pipelines.
last release 2026-08-12 (2 days) · last repo commit 2026-08-14 · 1,182 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 157,816 downloads/mo, #10,744 on PyPI
Alternatives
Verify before relying
pip install guarddog
guarddog pypi scan requests
guarddog pypi scan requests --version 2.28.1
guarddog pypi verify requirements.txt --output-format=json- Accuracy and false-positive rate of YARA rules and risk scoring model in real-world supply chain scenarios
- Performance characteristics when scanning large monorepos or dependency trees with hundreds of packages
- Coverage and detection capability for emerging or novel malware patterns not yet in the rule set
What it is and what it does
GuardDog is a static analysis tool that downloads and scans open source packages across multiple ecosystems (PyPI, npm, Go, Rust, RubyGems, GitHub Actions, VSCode extensions) to detect supply chain attacks. Rather than flagging every suspicious pattern independently, it uses a risk-correlation model: it identifies both code capabilities (what the package can do, like network access) and threat indicators (suspicious domains, obfuscation), then flags actual risks only when both appear in the same file or across related files. This reduces alert fatigue by distinguishing between legitimate functionality and genuine malicious intent.
The tool runs YARA rules against package source code and analyzes metadata to score packages on a 0-10 risk scale based on attack chain completeness, specificity, and sophistication. Scans execute inside a kernel-level sandbox (Landlock on Linux, Seatbelt on macOS) to prevent malicious code from executing during extraction or analysis. It supports scanning remote packages, local archives, directories, and S3 buckets, with output in JSON or SARIF format for CI/CD integration.
Use it for
- Scan dependencies in a requirements.txt or package.lock file before deployment to catch known malicious packages
- Integrate into CI/CD to automatically flag high-risk packages during pull requests or builds
- Triage a suspected compromised package by scanning it locally to understand its capabilities and threat indicators
- Verify the security posture of third-party packages before adding them to a monorepo or internal registry
- Generate SARIF reports for integration with security dashboards or SIEM systems like Datadog
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
GuardDog is actively maintained, has no known vulnerabilities, and fills a specific gap in supply chain security by correlating code capabilities with threat indicators rather than generating false-positive noise. The sandboxed scanning protects against execution during analysis. Install it if you need to audit dependencies across multiple package ecosystems or integrate package security checks into CI/CD; skip it if you only use a single ecosystem and already have ecosystem-specific tooling.
Install
guarddog on PyPI
Before you install
Low friction installation via pip or uvx; actively maintained with recent releases. Requires modern Python (3.10+) and 18 runtime dependencies including boto3, pygit2, and yara-python. Sandboxed scanning on Linux and macOS protects against malicious code execution during analysis.
Requires Python 3.10+. Sandboxed scanning (default) requires Linux Landlock or macOS Seatbelt; use --no-sandbox to disable. Windows requires Docker.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for integration into security workflows and CI/CD pipelines.
Quickstart
pip install guarddog
guarddog pypi scan requests
guarddog pypi scan requests --version 2.28.1
guarddog pypi verify requirements.txt --output-format=json
Verify before relying
- Accuracy and false-positive rate of YARA rules and risk scoring model in real-world supply chain scenarios
- Performance characteristics when scanning large monorepos or dependency trees with hundreds of packages
- Coverage and detection capability for emerging or novel malware patterns not yet in the rule set
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 18 packagesboto3clickconfigparserdisposable-email-domainsnono-pypackagingprettytablepygit2python-dateutilpython-whoispyyamlrequestssemantic-versiontarsafetermcolortyping-extensionsurllib3yara-python |
| Maintenance | Actively maintained 2 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 157,816 / month, #10,744 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: guarddog-3.2.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “malicious package detection”
- guarddogGuardDog is a CLI tool that scans PyPI, npm, Go, Rust, RubyGems,…
- cisco-ai-mcp-scannerScans MCP (Model Context Protocol) servers and tools for security…
- cisco-ai-skill-scannerScans AI Agent Skills for prompt injection, data exfiltration, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also safety · skylos · socketsecurity · pysentry-rs · kingfisher-bin · ca9 · picklescan · clamd · checkov · plugin-scanner