Toolip
Local-First Security, Dependency Intelligence & Secure Developer Workflows
Overview
Toolip v2.2.1 is a TypeScript security CLI for JavaScript and TypeScript projects. It keeps analysis local by default while combining supply-chain intelligence, exact resolved dependency analysis, secret detection, compiler-backed AST checks, Git security, SBOM generation, encrypted local secrets, safe dependency upgrades, static reporting and a read-only MCP interface.
Platform proof
V2.2.1 unifies vulnerability analysis and dependency health around one exact resolved npm graph instead of treating manifest ranges as installed versions. The same inventory powers OSV vulnerability matching, health, tree output, SBOM relationships, install-script inspection and reachability. Repository analysis is bounded through shared discovery, guarded reads, analyzer deadlines, cancellation, partial-failure isolation and deterministic output.
Key capabilities
Technical profile
Architecture signal
Engineering focus
Skills
Technical note
Toolip is deliberately measurement-aware: an unmeasured dimension is never scored as perfect, provider failures remain explicit, dependency identity comes from the resolved graph, and repository growth is bounded by controlled discovery and analyzer budgets. The encrypted vault uses AES-256-GCM with scrypt-derived keys and atomic locked persistence; MCP paths are canonicalized to prevent traversal and symlink escape. Node 22/24 CI runs across Linux, macOS and Windows with packed-artifact release verification.
Discuss this project
Open to backend, platform, API, tooling, CMS, and business software conversations.
Work emailwilliams@zivoralabs.xyz
link Book 30min call