For developers

Your .npmrc picks up a token. The rest of your day doesn't change.

Chainsaw is a registry proxy, not a plugin and not an agent. A pass looks no different. A block tells you which rule fired and who can unblock it.

What you'll see

Same install command, one new check

  1. 01 · You, or CI

    npm install

    pip, Maven, Cargo, Go, Docker: unchanged

  2. 02 · Chainsaw proxy

    • vulnerability rules
    • license and version rules
    • typosquat and attack signals
  3. Blocked

    the error names the rule and who can unblock it

    Allowed

    repeat installs serve from cache

Common worries

What's actually true

WorryWhat's true
Builds get slowerRepeat installs serve from Chainsaw's cache. CI usually gets faster.
I can't debug a blockThe error names the rule, the reason and the exception reviewer.
Workspaces breakIt proxies the registry, so pnpm, Yarn, Nx and Turborepo work unchanged. Lockfiles stay the same.
A new rule breaks meAsk for new rules in monitor first. The audit log records what would have been blocked.
Setup eats a dayOne client credential per machine. chainsaw install-hook writes it for you.
My agent picks packagesIt can ask Chainsaw's MCP server first, with only the scope an admin grants it.

Agent setup: /for-agents/

Config

Point your package manager at Chainsaw

Paste one into your config, or let chainsaw install-hook write it.

.npmrc
registry=https://chain305.com/chainproxy/repository/@default/npmjs/
//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=${CHAINSAW_TOKEN}
always-auth=true
pip.conf
[global]
index-url = https://${CHAINSAW_TOKEN}@chain305.com/chainproxy/repository/@default/pypi/simple/
trusted-host = chain305.com
~/.m2/settings.xml
<mirrors>
  <mirror>
    <id>chainsaw</id>
    <url>https://chain305.com/chainproxy/repository/@default/maven-central/</url>
    <mirrorOf>*</mirrorOf>
  </mirror>
</mirrors>
~/.docker/config.json
{
  "auths": {
    "chain305.com": {
      "auth": "${BASE64_TOKEN}"
    }
  }
}
.cargo/config.toml
[source.crates-io]
replace-with = "chainsaw"

[source.chainsaw]
registry = "https://chain305.com/chainproxy/repository/@default/crates-io/"
token = "${CHAINSAW_TOKEN}"
Go GOPROXY
export GOPROXY=https://${CHAINSAW_TOKEN}@chain305.com/chainproxy/repository/@default/gomod/,direct
export GOSUMDB=off

Evaluating for your team?

Free plan is permanent; ten minutes to wire one repo

Point one .npmrc at Chainsaw, install a package on a CVE list, and read the error yourself.