517,150 packages matching “default-deny”
@amritk/resolve-refs
v0.9.0 · 9 days ago
Resolve and inline JSON Schema / OpenAPI $refs — internal, cross-file, and remote — with session caching and a default-deny SSRF guard.
No known vulnerabilities
@bonniernews/stayput
v0.1.4 · 9 days ago
Default-deny network guard for Node.js test environments — blocks non-local TCP at the socket level.
No known vulnerabilities
@nationaldesignstudio/rampart
v0.1.3 · 3 months ago
Rampart — client-side PII redaction for AI assistants: deterministic recognizers + a 14.7 MB ONNX classifier (transformers.js), default-deny policy, and reversible placeholders. Runs entirely in the browser.
No known vulnerabilities
@lazyingart/lazyedge
v0.4.0 · 1 month ago
A lightweight, default-deny reverse edge for safely connecting private compute to public domains.
No known vulnerabilities
occ-mcp-proxy
v2.6.0 · 6 months ago
Policy enforcement for AI tool calls. Default-deny control for any MCP server.
No known vulnerabilities
@odla-ai/chat
v0.13.4 · 14 days ago
Realtime messaging and project discussions on odla-db: project channels, post threads, bottom thread cards, scoped live updates, DMs, and AI participants over one default-deny graph.
No known vulnerabilities
@alter-ai/alter-sdk
v0.27.0 · 5 days ago
Official TypeScript SDK for Alter Vault — privileged access for AI agents: vaulted credentials, default-deny policy, approval policies, and an audit trail for every call made through Alter
No known vulnerabilities
nestjs-apikey-auth
v1.0.2 · 10 days ago
API-key authentication for NestJS — opaque hashed-at-rest keys, scopes, expiry, instant revocation, and a default-deny guard for machine & third-party callers.
No known vulnerabilities
@zeroness/egress
v0.4.0 · 1 month ago
zeroness Egress Worker — default-deny outbound proxy that enforces Broker decisions and injects brokered identity.
No known vulnerabilities
@fonderie/sse
v0.2.8 · 5 hours ago
Server-Sent Events delivery to frontends — clients subscribe to all or individual events, each brick's event catalog decides who may receive what (default deny), and fan-out works across instances. Push is additive: apps never wait on it.
No known vulnerabilities
@adjudicate/pack-cli-agent
v0.1.4 · 3 months ago
Default-deny CLI/terminal agent Pack — composes the shipped command-risk guard with allowlist EXECUTE, credential ESCALATE, maintenance DEFER, and a fail-closed default-deny sink.
No known vulnerabilities
scriptinel
v0.1.2 · 9 months ago
Install script firewall for npm - default-deny lifecycle scripts with explicit, reviewable allowlists
No known vulnerabilities
@pactmark/policy
v0.2.0 · 1 month ago
Portable default-deny policy, grants, risk gates, and revocation for Pactmark
No known vulnerabilities
@riceawa/dsh-lan-gateway
v0.7.1 · 2 days ago
LAN/internet reverse-proxy gateway for the DeepSeek Harness web GUI: binds 0.0.0.0 and forwards to the loopback dsh web server. Default-deny: every source (loopback, LAN, internet) must sign in with an HMAC session cookie unless lanPasswordless is explici
No known vulnerabilities
@caisson-sh/tool-exec
v0.4.1 · 7 days ago
Governed tool-call / sandboxed-exec primitive for Agentic-Dev: default-deny allowlist + Zod-strict argument schemas + execFile arg-arrays only (no shell) + structured argument provenance.
No known vulnerabilities
@civaapple/qi-capability
v0.5.1 · 2 months ago
Default-deny Qi capability leases, credentials, delegation, and redaction
No known vulnerabilities
@acegalaxy/voice-gateway
v0.1.2 · 5 months ago
OpenAI Whisper wrapper with cost cap, rate limit, default-deny authz, queue, and audit log. Production-ready STT for Telegram bots.
No known vulnerabilities
@acegalaxy/ott-gateway
v0.1.2 · 5 months ago
Inbound message security gateway for bots — 5-layer default-deny (caller-validator, identity-resolver, rate-limit, audit, forward) for Telegram/WhatsApp/WeChat and other OTT platforms.
No known vulnerabilities
@ever-works/browser-automation-plugin
v1.0.1 · 3 days ago
Headless browser automation for Ever Works - navigate, extract, screenshot and act on web pages via Playwright, behind a default-deny navigation allowlist that is re-checked on every redirect hop
No known vulnerabilities
mcp-server-attestation
v0.2.0 · 3 months ago
Library for Ed25519-signed MCP tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Layer-2 mitigation for marketplace-poisoning, CVE-2025-69256, CVE-2025-61591.
No known vulnerabilities