Anti Reversing Techniques
Understand anti-reversing, obfuscation, and protection techniques encountered during software…
Forged from real client work, proof attached. Pick a piece or take the whole system.
Browse the full catalog → Browse ready-made kits → Build your own set →Score npm/PyPI/Cargo dependency risk before install/upgrade using bomdrift SBOM diff…
Score the supply-chain risk of npm, PyPI and Cargo dependencies at the moment they change in a pull request, before install or upgrade merges. It answers a different question than scan-everything tools: not 'what vulnerabilities exist' but 'what changed in this diff and should I worry?' Six signals run together: SBOM diff, typosquat detection, maintainer-age scoring, CVE prioritization and license policy, to catch the long-game attacks that traditional scanners miss.
Prices include 20% VAT. · Forged on real agency work · one-time, no lock-in
Inside the run · no black box
The xz backdoor came in through a dependency change that looked routine. This gate diffs byte-deterministic SBOMs on every lockfile PR, runs six risk signals from CVE-with-EPSS to typosquat distance, and blocks the merge instead of advising.
supply-chain-risk-scoring · core
core active · 6 lines
Gating a Renovate or Dependabot auto-merge PR with a risk score
Catching a typosquatted transitive dependency before it lands
Flagging a freshly-created maintainer account on a critical package
Reviewing a major version bump that skips semver ranges
Enforcing a license policy that denies GPL/AGPL in commercial code
Producing a byte-deterministic SBOM diff as a sticky PR comment
Drag time forward. Watch what stays.
Forever
That's what owning means.
ai writing tool: subscription
expired · access lostanalytics suite: subscription
expired · access lostdesign platform: subscription
expired · access lost(nothing left)
See exactly what changed in a dependency diff before you merge it
license: perpetualStop typosquat and maintainer-takeover attacks that pure CVE scanners miss
license: perpetualBlock auto-merge bots when a package suddenly changes its maintainer set
license: perpetualKeep noise low with findings-only comments and CRITICAL/HIGH thresholds
license: perpetualsubscriptions expire · deeds don't
Pick a piece up. Watch it work.
A defensive CLI wrapper that snapshots SBOMs, diffs them and posts a sticky PR comment
6 parts · one working system · ships instantly by email
Teams reviewing dependency upgrade PRs who want a diff-time gate alongside their scan-everything tooling.
then this was forged for you.Universal by design: these run in any AI. Delivered in the open Agent Skills + MCP format (native in Claude); ChatGPT, Gemini, Cursor and Copilot adapt the same files their own way.
It answers a different question. Scanners tell you what vulnerabilities exist across your whole inventory; this scores what changed in a single PR diff, typosquatted packages, fresh maintainer accounts, license flips, the long-game attacks CVE scanners miss. It is designed to run alongside your existing tooling, including gating the Renovate or Dependabot auto-merge itself.
Two of the six signals handle that: a Jaro-Winkler string-distance detector compares new dependency names across eight package ecosystems, and a Bayesian maintainer-risk scorer flags young accounts and recent ownership changes, the xz pattern. Both run on the SBOM diff, so they fire on the exact components a PR introduces.
No, and that is deliberate. It is a diff-time gate: it scores only what changed in a pull request before merge. Continuous full-inventory scanning, runtime monitoring, and vulnerability management stay with your scan-everything tools; this fills the gap they leave at the moment of change.
By email right after purchase: ready to run, downloaded instantly, no setup wait.
A one-time purchase; no subscription or hidden fees. VAT (20%) is included.
As a digital product, it can’t be refunded once downloaded. That’s why we show exactly what’s inside and who it’s for, right here.