Observed arrival · 2026-10-09
Cordon checks packages and agents before execution
Cordon offers an open-source scanner for dependencies, repositories, pipelines, MCP servers, and infrastructure, with a cloud product for findings and policy.
- For
- Software supply-chain and agent security teams
- Worth noticing
- Its published benchmark says 249,646 known-malicious package records were caught across 287,899 checks, with none missed.
Field notes
The scanner is presented as a CLI tool installed with `pipx install cordon-scanner`; the page says it reads repositories, lockfiles, packages, images, CI pipelines, infrastructure, and secrets without executing code, with offline use available. Its benchmark section names scripts for malicious-package, lockfile-agreement, and agent-threat tests. A cloud view is also shown with repository coverage, open findings, SLAs, and rescan controls; the extract does not establish that the displayed figures are live customer data.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue