Worker analysis
Anvil Registry queues expensive analysis outside the install request path. The worker unpacks tarballs, compares versions, and produces evidence that feeds deterministic policy decisions.
What the worker analyses
Manifest checks
- Package name, version, and description changes.
scriptsfield: new or changed lifecycle scripts.dependencies,devDependencies,peerDependencies,optionalDependencieschanges.- New dependencies added in a patch version.
bin,files,repository,license, andmaintainerchanges.
Install script checks
Lifecycle scripts are the most common install-time risk surface:
preinstallinstallpostinstallprepareprepublishprepublishOnly
The worker flags new or changed scripts and scans their contents for suspicious patterns.
Code pattern checks
Static analysis of the unpacked tarball looks for:
child_processusage (exec,spawn,fork).- Direct
process.envaccess. fsmodule usage in install paths.http/httpsorfetchcalls in install paths.net.connectordnslookups.eval,Function, orsetTimeoutwith string arguments.Buffer.from(base64)decoding followed by execution.- Shell piping (
| sh,| bash).
File tree checks
- New binary or executable files.
- Unexpected size changes.
- Minified or obfuscated files.
- Encoded blobs (base64 strings in non-binary files). Verified inline PNG, JPEG, GIF, WebP, and passive SVG data URIs are treated as assets rather than executable obfuscation; malformed, falsely labelled, or active SVG content is still flagged.
- Hidden files (dot-prefixed).
- Unusual paths (traversal attempts, temp directories).
- Credential-looking files (
.npmrc,.ssh,.aws,.env).
Name-squatting checks
The worker compares low-adoption package names against the popular package index:
- Typo variants: missing character, extra character, transposed characters.
- Hyphen and underscore swaps.
- Pluralisation differences.
- Visual similarity (homoglyphs).
- Scope confusion (
@scope/pkgvs@scop/pkg). - Ecosystem confusion (package names that mimic well-known tools).
Algorithms used: Damerau-Levenshtein distance, Jaro-Winkler similarity, token normalisation.
Comparison strategy
By default, the worker compares the target version against the previous three versions. This surfaces:
- What changed.
- Whether the change fits the release type (patch, minor, major).
- Whether install-time behaviour changed when runtime behaviour should not have.
Analysis output
The worker produces a structured report stored in Postgres and linked to the package decision:
- Signal list with severity.
- File references where available.
- Diff summaries against previous versions.
- Name-squatting match results.
- Provenance status.
LLM review context
When enabled, the worker can send structured evidence to an LLM reviewer. The model output is validated against a Zod schema and stored as review context. It never overrides the deterministic policy decision.
Cache identity
Analysis reports are cached by:
- Package name.
- Version.
- Tarball integrity or hash.
- Analysis engine version.
- Policy version.
If any of these change, the cached report is not reused. This prevents a decision for one artifact from silently applying to a different artifact.
Registry releases advance the analysis engine version when detector behaviour changes. The gateway then treats reports from the older analyser as stale and queues current analysis when the exact tarball is requested.
Queue targeting and reputation data
Metadata policy still evaluates every published version, but automatic deep analysis from a metadata request is limited to the version behind latest. Historical, compatibility, and prerelease dist-tags are analysed when their exact tarball is requested or an operator explicitly queues them through a lockfile scan or manual review.
npm download counts are optional reputation context. Anvil caches them for 15 minutes, coalesces duplicate package lookups, limits concurrent upstream requests, and retries transient failures. If the downloads API remains unavailable, analysis continues without that signal.
Limitations
- Analysis is asynchronous. The gateway may allow or quarantine a package while analysis is pending.
- Very large tarballs may hit worker timeout limits.
- Private package metadata is excluded from LLM review by default.
- The worker does not execute install scripts. Static analysis only.