BETA Shoulder is in beta — Findings may sometimes be wrong. Your feedback shapes what we fix next. Share feedback
v0.1

Install Shoulder CLI

Free to use. Your source code never leaves your machine — dependency lists are checked against our ecosystem intelligence, but your code stays local.

Free to use
Code stays local
No account needed
Transparency report →
npm The fastest way to get started
$ npm install -g @shoulderdev/cli

Requires Node.js 18+. Or try instantly with npx @shoulderdev/cli scan .

binary Standalone download, no Node.js needed
Download
Run
SHA-256
Verify

All releases published at github.com/shoulderdev/binaries

Quick start

1 Scan your project for threats
$ shoulder scan .
2 Check a specific package
$ shoulder scan --ecosystem
3 Try without installing
$ npx @shoulderdev/cli scan .

We're working with a small number of engineering and security teams to shape Shoulder in real workflows. Design Partners →