Decision Workspace
npm_sentinel vs sigil-cli vs npmls
Side-by-side comparison of Rust crates
42
npm_sentinel
experimentalv0.2.0
A CLI tool to detect supply chain attacks in npm packages by analyzing lifecycle scripts and registry metadata.
44
sigil-cli
experimentalv1.0.5
Automated security auditing for AI agent code - quarantine-first scanning for pip, npm, git repos, and MCP servers
41
npmls
experimentalv0.4.0
Fast cross-platform scanner for npm modules and malicious packages
Core Metrics
| npm_sentinel | sigil-cli | npmls | |
|---|---|---|---|
| Health Score | 42 | 44 | 41 |
| Total Downloads | 72 | 29 | 1.2K |
| 30d Downloads | 7 | 7 | 5 |
| Dependents | 0 | 0 | 0 |
| Releases | 2 | 2 | 4 |
| Last Updated | 121d ago | 34d ago | 197d ago |
| Age | 4m | 1m | 6m |
Health Breakdown
npm_sentinel
Maintenance
11
Quality
13
Community
6
Popularity
2
Documentation
10
sigil-cli
Maintenance
12
Quality
14
Community
6
Popularity
2
Documentation
10
npmls
Maintenance
16
Quality
5
Community
6
Popularity
4
Documentation
10
Technical Details
| npm_sentinel | sigil-cli | npmls | |
|---|---|---|---|
| Version | 0.2.0 | 1.0.5 | 0.4.0 |
| Stable (≥1.0) | ✗ No | ✓ Yes | ✗ No |
| License | MIT | Apache-2.0 | MIT |
| Dependencies | 7 | 16 | 24 |
| Crate Size | 16KB | 47KB | 52KB |
| Features | 0 | 0 | 0 |
| Yanked % | 0.0% | 0.0% | 75.0% |
| Edition | 2021 | 2021 | 2021 |
| MSRV | — | — | — |
| Owners | 1 | 1 | 1 |
Links
Quick Verdict
- •sigil-cli leads with a health score of 44/100, but none of the options score above 80.
- •npmls has the most downloads (1.2K), suggesting wider adoption.
- •npm_sentinel, npmls are pre-1.0 — API may change.