2026-10-11 17:11 UTC

Independent testing will determine whether Kenwea’s sandboxed npm install-script checks and signed, tarball-bound verdicts reliably identify supply-chain risk before agents install MCP-related dependencies.

state: expiredheat: lowuncertainty: highconvergesscott: lowagentic-security npm-supply-chain developer-toolsMyzuraKenwea

What is this?

Kenwea is presented as a developer tool from Myzura that sandboxes npm package installation scripts and produces signed verdicts bound to package tarballs, with an apparent focus on dependencies used by agents and MCP tooling. The supplied web results establish the broader risk—malicious npm lifecycle hooks and compromised packages—but provide no independent testing of Kenwea itself, so its detection reliability, sandbox containment, and verdict integrity remain unverified. Details about the tool and its creators are thin and come primarily from the cited Show HN post and package README rather than the web snippets.

Why it matters to Scott

Kenwea independently combines two positions Scott already holds: sandbox untrusted installation and bind reusable trust claims cryptographically to exact artefacts. However, the supplied evidence establishes only an unverified implementation claim from a thinly documented vendor, so it is currently another example of Scott’s architecture rather than evidence that would change what he builds or argues.
ip:framework.agent-provenance-stackip:concept.sandboxed-executionip:concept.cryptographic-trustdev:concept.version-bound-ai-assessmentradar:concept.software-supply-chainradar:concept.sandboxingradar:concept.coding-agent-securityradar:concept.mcp-securityradar:senv-python-agent-sandboxradar:traceseal-signed-agent-receipts
queries asked of Scott's wikis
  • sandboxing dependency installation for coding agents
  • MCP dependency supply-chain security
  • signed attestations and content-addressed package verdicts
  • agent harness trust before tool installation
  • npm lifecycle-script containment and network isolation
  • reusing security verdicts across exact package artifacts

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Sandbox the install step of any NPM packageMyzura10
🟧 echo.other ⭐The package README is the earliest public primary artifact matching the HN post's install-sandbox feature. It says the tool resolves the exaKenwea Protocol——

Interpretation history

Decision trace