DEVELOPER SECURITY TOOLING · v2.2.1

Toolip

Local-First Security, Dependency Intelligence & Secure Developer Workflows

Overview

Toolip v2.2.1 is a TypeScript security CLI for JavaScript and TypeScript projects. It keeps analysis local by default while combining supply-chain intelligence, exact resolved dependency analysis, secret detection, compiler-backed AST checks, Git security, SBOM generation, encrypted local secrets, safe dependency upgrades, static reporting and a read-only MCP interface.

Platform proof

V2.2.1 unifies vulnerability analysis and dependency health around one exact resolved npm graph instead of treating manifest ranges as installed versions. The same inventory powers OSV vulnerability matching, health, tree output, SBOM relationships, install-script inspection and reachability. Repository analysis is bounded through shared discovery, guarded reads, analyzer deadlines, cancellation, partial-failure isolation and deterministic output.

Key capabilities

Exact Dependency GraphOSV Vulnerabilitiesdeps.dev Health + LicensesCompiler-Backed AST ScanSecret + Git History ScanCycloneDX / SPDX SBOMMeasurement-Aware ScoreStaged Pre-CommitAtomic AES-256-GCM VaultRead-Only MCPWorktree Upgrade PRs

Technical profile

TypeScriptNode.jsCommander.jsVitestZodNode Crypto APIsGit Integration

Architecture signal

Developer Project ↓ Shared Project Context ├── Resolved Dependency Inventory └── Bounded Source Inventory ↓ Canonical Analyzer / Finding Contract ↓ Bounded Execution Engine ├── deadlines + cancellation ├── failure isolation └── deterministic aggregation ↓ CLI / Pre-Commit / Watch / Reports / MCP ↓ Atomic Encrypted Vault + Isolated Upgrade Worktrees

Engineering focus

Developer security toolingSupply chain securitySecret detectionStatic analysis conceptsCLI architectureSecure developer workflows

Skills

TypeScriptNode.jsCommander.jsSecurity EngineeringSupply Chain SecurityNode CryptoGit Workflows

Technical note

Toolip is deliberately measurement-aware: an unmeasured dimension is never scored as perfect, provider failures remain explicit, dependency identity comes from the resolved graph, and repository growth is bounded by controlled discovery and analyzer budgets. The encrypted vault uses AES-256-GCM with scrypt-derived keys and atomic locked persistence; MCP paths are canonicalized to prevent traversal and symlink escape. Node 22/24 CI runs across Linux, macOS and Windows with packed-artifact release verification.

Discuss this project

Open to backend, platform, API, tooling, CMS, and business software conversations.

Work emailwilliams@zivoralabs.xyz

link Book 30min call