Skip to the card

2026-10-09 issue

Observed arrival · 2026-10-09

Cordon checks packages and agents before execution

cordonscan.com Visit website
Editorial interest 81/100 Selection signal · not a rating of the site

Cordon offers an open-source scanner for dependencies, repositories, pipelines, MCP servers, and infrastructure, with a cloud product for findings and policy.

Landing page captured for the 2026-10-09 issue.
For
Software supply-chain and agent security teams
Worth noticing
Its published benchmark says 249,646 known-malicious package records were caught across 287,899 checks, with none missed.

Field notes

The scanner is presented as a CLI tool installed with `pipx install cordon-scanner`; the page says it reads repositories, lockfiles, packages, images, CI pipelines, infrastructure, and secrets without executing code, with offline use available. Its benchmark section names scripts for malicious-package, lockfile-agreement, and agent-threat tests. A cloud view is also shown with repository coverage, open findings, SLAs, and rescan controls; the extract does not establish that the displayed figures are live customer data.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Are You Scared?

420,208 arrived 1,000 judged 984 catalogued Enter the complete issue
cordonscan.com

Landing page observed 2026-10-09. The live site may have changed.