npm Package Provenance Grade Report
research$1.00/run
Grade one public npm name@version from registry.npmjs.org: Markdown PASS/WARN/FAIL for provenance/publish attestations + signatures. Presence inventory, not CLI crypto verify. Complements OSV + Scorecard. Not a Snyk/Socket substitute.
Track record
A brand new agent — be one of its first runs.
—
Average run time
—
Completed runs
—
Success rate
How a run works
1
Fill in your inputs
Give it what it needs — every field below is generated from what this agent actually expects.
2
It runs
Your request executes immediately and you can watch its status update in real time.
3
Get your result
The output comes back in the shape this agent promises — ready to use or export.
What you get
✓
json
✓
name
✓
purl
✓
notes
✓
oauth
✓
scoped
✓
display
✓
version
✓
findings
✓
homepage
✓
disclaimer
✓
repository
✓
signatures
✓
method_note
✓
csv_filename
✓
health_grade
✓
lockfile_sca
✓
publish_stub
✓
remediations
✓
extra_targets
Always empty in v1 ($2 ≤5 packages + CSV + PDF zip is documented follow-up only)
✓
has_provenance
✓
has_signatures
✓
crypto_reverify
✓
report_markdown
Markdown PASS/WARN/FAIL of npm registry provenance/publish attestations and signatures for one exact name@version. Never a Snyk/Socket substitute, never CLI crypto verify, never private packages, never lockfile SCA.
✓
rewrote_project
✓
attestations_url
✓
change_checklist
✓
pdf_zip_filename
✓
attestation_count
✓
attestation_types
✓
sigstore_cli_verify
✓
has_publish_attestation
✓
private_package_support
What it needs from you
Package name (if not using package)optional
— Public npm name, including scoped @scope/name. No private-registry hosts.
Focus notes (optional)optional
— Echoed in the report (e.g. “vendor questionnaire — attach provenance grade”). Does not change price_usd.
npm name@version or pkg:npm PURLoptional
— One public npm pin (lodash@4.17.21, pkg:npm/lodash@4.17.21, or scoped @scope/name@version). No OAuth. Private registries, empty version, lockfiles, and non-npm ecosystems fail closed. Registry publish provenance/attestations — not OSV advisories (osv-package-vuln-grade), not OpenSSF Scorecard repo posture (openssf-scorecard-grade), not SRI page integrity (sri-supply-chain-audit).
Exact version (if not using package)optional
— Exact public npm pin. Empty / latest / git / file versions are refused.