Skip to main content

AI-powered supply chain security. Blocks malicious packages at install and import time. Works with Claude Code, Cursor, Devin, and every AI coding agent.

Project description

stillrunning

Supply chain security for developers and AI coding agents. Blocks malicious packages at install AND import time.

Version Protected by stillrunning Python License

What's new in v2.0

  • Python import hook — blocks at execution, not just install
  • MCP server — Claude Code checks packages before installing
  • Interactive Telegram approvals — default deny, one tap to allow
  • Works with every AI coding agent — Claude Code, Cursor, Devin, Replit, Windsurf, Aider
  • Autonomous mode for CI/CD pipelines
  • Hash verification against PyPI registry

What it blocks

Attack Vector Status
pip install malicious-pkg Blocked
pip3 install malicious-pkg Blocked
python3 -m pip install malicious-pkg Blocked
npm install malicious-pkg Blocked
pip install -r requirements.txt Scans all packages
import malicious_pkg Blocked (via hook)
from malicious_pkg import x Blocked (via hook)

Known limitations

Gap Workaround
/usr/bin/pip direct binary Use import hook for coverage
Virtual env pip Activate intercept or use import hook
Conda/poetry/pipx Manual activation required

Quick start (30 seconds)

pip install stillrunning
stillrunning --setup

Import protection (one line)

import stillrunning.hook

Always-on import protection

stillrunning --install-hook

Telemetry

stillrunning sends an anonymous heartbeat every 6 hours if you opt in during setup. No email, IP, or log content — just a random ID so we know how many agents are running.

Disable by setting telemetry: false in stillrunning.yaml.

Autonomous mode (CI/CD + AI agents)

export STILLRUNNING_APP_NAME="my-app"
export STILLRUNNING_TELEGRAM_TOKEN="..."
export STILLRUNNING_CHAT_ID="..."
stillrunning --autonomous

MCP / Claude Code integration

Add to ~/.claude/settings.json:

{
  "mcpServers": {
    "stillrunning": {
      "type": "url",
      "url": "https://stillrunning.io/mcp",
      "name": "stillrunning"
    }
  }
}

Claude Skill

Install the stillrunning skill for automatic package checking in every Claude Code session:

github.com/johhnyg/stillrunning-skill

Works with every AI coding agent

Claude Code, Cursor, Devin, Replit, GitHub Copilot, Windsurf, Aider

Setup: stillrunning.io/agent-setup

Commands

stillrunning --setup          # 3-minute setup wizard
stillrunning --doctor         # Health check
stillrunning --install-hook   # Enable always-on import protection
stillrunning --autonomous     # CI/CD mode (no prompts)
stillrunning --allow <pkg>    # Allow a blocked package
stillrunning --block <pkg>    # Manually block a package
stillrunning whitelist add <pkg>    # Add to whitelist
stillrunning whitelist remove <pkg> # Remove from whitelist
stillrunning whitelist list         # Show whitelist

Pricing

Tier Price AI Scans Features
Free $0 0 Blocklist checks (10/day)
Personal $9/mo 0 Guard daemon, 1 machine, blocklist
Basic $29/mo 0 Dashboard, 3 machines, Telegram, blocklist
AI $49/mo 100/day AI package review, unlimited machines
Enterprise $499/mo 10,000/day SIEM, SSO, compliance
Enterprise+ $2,499/mo Unlimited Dedicated support, on-prem

Badge

![Protected by stillrunning](https://stillrunning.io/badge/protected)

Links

License

MIT License

Patent Pending — US Provisional Application filed April 12, 2026

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stillrunning-2.1.0.tar.gz (63.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

stillrunning-2.1.0-py3-none-any.whl (66.7 kB view details)

Uploaded Python 3

File details

Details for the file stillrunning-2.1.0.tar.gz.

File metadata

  • Download URL: stillrunning-2.1.0.tar.gz
  • Upload date:
  • Size: 63.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for stillrunning-2.1.0.tar.gz
Algorithm Hash digest
SHA256 8ec983b25111d164d299d1495f3ca320525d541e509bfcd60e5b72b513b6f169
MD5 f5567690b1cd3d85e0f272305cd136d8
BLAKE2b-256 2b27b2e93efa341917b7b2c90b6d3b3ace38c95b90b61fcc8c516a1798df18dc

See more details on using hashes here.

File details

Details for the file stillrunning-2.1.0-py3-none-any.whl.

File metadata

  • Download URL: stillrunning-2.1.0-py3-none-any.whl
  • Upload date:
  • Size: 66.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for stillrunning-2.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 933251633297c0e75b52b1d5c38b91e87c59cfa900fe58a5da05ff0f31e011dd
MD5 8937212944546fde8d2662c09e695a18
BLAKE2b-256 07d1c3692486d8891e0ebbdcace01a964929f72f40dca6b01a0f6a789ed1b918

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page