From the thesis to production
The thesis scored known vulnerabilities.
The product extends it to day-zero malware.
Everything below started as a chapter. The one thing the thesis did not attempt, catching a malicious package that has no CVE at the moment of install, is what the same scorer does today at the proxy.
Cross-source database, 1,088,564 records→1.3M+ vulnerabilities, 207K+ malicious packages, 10M+ dependency edges, refreshed continuously
XYZ score, 40 / 30 / 20 / 10 weighting→Six parallel detection signals fused by a cross-signal scorer into allow, alert, quarantine or block
Local CLI agent, xyz scan→The xyz CLI on PyPI, the install-time proxy, the VS Code extension and the CI/CD gate
Attack-chain detection, ProxyShell and HAFNIUM→Campaign tracking mapped to MITRE ATT&CK, and wave correlation across registries
Future work: AI committee evaluation→AI-written alert review and commit-level code reading on every pull request