← Home

@forwardimpact/guide

Conversational agent for engineering framework guidance — How do I find my bearing?

33
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

dickolsson

Keywords

agent-aligned-engineering-standardcareer-developmentai-agentskill-assessmentknowledge-platformconversational-agentengineering-excellencerag

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@forwardimpact/libtelemetry AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): 127.0.0.1 is localhost OAuth PKCE callback server — standard auth pattern, not suspicious. ai
phantom-deps phantom-dep:@forwardimpact/librc AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/svcmcp AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/libutil AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/svcgraph AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/svctrace AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/svcvector AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/libcodegen AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
phantom-deps phantom-dep:@forwardimpact/svcpathway AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic unreliable for transitive/indirect monorepo usage. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped @forwardimpact package; name similarity to uuid is coincidental, not impersonation. ai

Versions (showing 33 of 33)

Version Deps Published
0.1.46 19 / 1
0.1.45 19 / 1
0.1.44 19 / 0
0.1.43 18 / 0
0.1.42 18 / 0
0.1.41 18 / 0
0.1.40 17 / 0
0.1.39 17 / 0
0.1.38 17 / 0
0.1.36 17 / 0
0.1.35 17 / 0
0.1.34 17 / 0
0.1.33 17 / 0
0.1.32 17 / 0
0.1.31 17 / 0
0.1.30 17 / 0
0.1.29 17 / 0
0.1.28 17 / 0
0.1.27 17 / 0
0.1.23 19 / 0
0.1.22 19 / 0
0.1.21 19 / 0
0.1.20 19 / 0
0.1.19 19 / 0
0.1.17 18 / 0
0.1.16 18 / 0
0.1.15 18 / 0
0.1.13 17 / 0
0.1.11 16 / 0
0.1.10 15 / 0
0.1.8 7 / 0
0.1.6 7 / 0
0.1.5 7 / 0

v0.1.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.