Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A software bill of materials (SBOM) can show zero new packages even when a coding agent has just installed them. An SBOM records what its generation process can see in the inputs and scope it scans; it is not automatically a live log of every installation in an agent’s working environment. To capture agent-installed dependencies, compare an inventory generated before the run with the packages actually present afterward, and record how and when each inventory was produced.
Axeploit’s 2026 headline reported “23 packages in a minute” and zero recorded by an SBOM. The article page was not independently verifiable, so that figure is a reported scenario—not a controlled test, independently confirmed incident, or general rate. The important question is how the SBOM was generated and what it was meant to cover.
Why can an SBOM show zero when packages were installed?
An SBOM is an inventory derived from particular inputs, such as a manifest, lockfile, repository dependency graph, or installed files. If an agent installs packages after the inventory is generated—or installs them somewhere the scanner does not inspect—the inventory may not include them.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →For example, npm documents that package-lock-only mode reads the package lock and ignores node_modules. npm also notes that dependency types omitted from an on-disk install can still be resolved and recorded in package-lock.json. A lockfile-based inventory and an installed-files scan can therefore describe different dependency states. See npm’s SBOM command documentation.
#1 Best Overall
Supported inputs vary by generator. AWS Inspector SBOM Generator lists JavaScript sources including package metadata under node_modules, package-lock.json, npm shrinkwrap, pnpm-lock.yaml, and yarn.lock; which source is available affects what can be represented. Check the generator’s supported artifact documentation rather than assuming every tool scans every file or directory.
Timing matters, too. GitHub describes repository SBOM export as an export of the current state of the repository’s dependency graph and documents generation through GitHub Actions. That is useful for repository and CI inventory, but it does not establish that an export captures every transient or out-of-band installation in an agent’s working environment. See GitHub’s repository SBOM documentation.
Rank #2
What does each inventory method actually capture?
| Method | Input or observation | What it can tell you |
|---|---|---|
| Manifest-based inventory | Declared package requirements | What the project requests, not necessarily every resolved or installed package. |
| Lockfile-based inventory | Resolved dependency lockfile | Dependencies represented in that lockfile, subject to the generator’s supported formats and coverage. |
| Installed-files scan | Package metadata or files in a selected directory | Packages visible in the scanned environment and location at scan time. |
| Repository dependency-graph export | Repository’s current dependency graph | A repository-oriented view; it does not by itself prove coverage of transient agent activity. |
These approaches answer different questions. A lockfile can preserve resolved dependency information even when the current install tree differs; a filesystem scan may see installed packages that are absent from a repository’s declared dependency state. Neither alone proves that every runtime component or installation event is represented.
Why treat agent setup instructions as a security boundary?
Agents may follow project setup instructions that run package-manager commands. Those instructions can influence package names, versions, and registries, so they are supply-chain inputs—not merely descriptive documentation.
Rank #3
A 2026 arXiv preprint studies package-install attacks delivered through ordinary setup instructions, including changes to a README, requirements file, or Makefile that direct an agent to an untrusted registry, a vulnerable version, or a plausible but wrong package name. Its abstract reports that registry-redirection attacks were missed in almost all evaluated harness/model combinations, with results varying by pairing. This is an abstract-level finding about the study’s evaluations, not a claim about every current coding agent. See the preprint abstract.
Before running an agent-provided or agent-followed install command, inspect the package name, requested version, and source. Pay particular attention to commands that add a registry, use a direct URL, or bypass the project’s usual package-manager workflow.
Rank #4
- STAY ON TOP OF EVERY MONTHLY BILL IN ONE PLACE – This bill tracker notebook is designed to help you organize rent, utilities, insurance, credit cards, subscriptions, and other recurring expenses in one easy system. As a practical monthly bill tracker and bill payment organizer, it helps households, busy families, couples, seniors, and anyone managing monthly bill payment keep everything clear, simple, and easy to review
- BUILT FOR REAL HOME AND PERSONAL FINANCE USE – More than a basic bill book organizer, this bill organizer notebook includes an annual overview, subscription and auto pay tracking pages, and detailed bill record pages for day-to-day use. Whether you use it at your kitchen counter, home office desk, family command center, or during monthly budgeting sessions, this monthly bill planner helps support better bill organization and a more consistent monthly bills payment checklist routine
- EASY-TO-USE BILL LOG PAGES THAT HELP REDUCE MISSED PAYMENTS – Each layout is made for simple tracking with space for paid status, bill name, due date, amount due, amount paid, unpaid balance, and notes. This bill payment checklist, payment tracker notebook, and monthly payment book gives you a clear way to track due dates, follow your payment plan, record your monthly payment plan, and keep important reminders in one organized place
- A4 SIZE WITH BLACK SPIRAL BINDING AND STORAGE POCKET – Designed as a durable bill organizer book and notebook for bills, this planner features a roomy A4 format that gives you more writing space than smaller books, plus black spiral binding for easy flipping and lay-flat use. A transparent storage pocket is placed before the back cover, making it convenient to hold receipts, statements, notices, or loose documents—ideal for anyone wanting a pay bills organizer book, monthly bill payment organizer, or bills book organizer monthly setup at home
- STURDY COVER, SMOOTH WRITING PAGES, AND A CLEAN PROFESSIONAL LOOK – Made with a 300 gsm coated paper cover and 100 GSM interior pages, this bill ledger book monthly for home is designed for regular monthly use while keeping a neat and polished appearance. It works well as a bill tracker notebook monthly bills organize solution for personal budgeting, household paperwork, and recurring bill management, making it a smart choice for anyone looking for a bills book, bill book monthly, best bill organizer book, or dependable bill payment record book
How can you capture dependencies installed during an agent run?
- Record a baseline. Generate an SBOM before the agent starts. Note the generator and version, command or workflow, input files and directories, dependency types, and timestamp.
- Run the agent in a defined environment. Keep the working directory and package-manager configuration identifiable so that post-run results can be compared with the baseline.
- Inventory after installation. Generate another SBOM using relevant supported lockfiles or dependency artifacts, and scan the environment where the agent installed packages when the generator supports that scope.
- Compare with the environment. Check the resulting inventory against packages actually present after the run. Where available, retain package name, version, source, and install-event details; this comparison helps identify packages that a repository-focused inventory did not capture.
- Investigate differences. For each unexpected package, trace the setup instruction or command that introduced it, verify the intended source, and decide whether to retain, remove, or explicitly declare it.
The comparison is an operational safeguard, not a guarantee that one scan sees every component. Record the scope and timing so another person can tell what the resulting SBOM does—and does not—represent.
Recommended Free Tools
What do lockfiles, hashes, registry rules, and SBOMs each protect?
- SBOM: An inventory artifact describing components visible to its generation process.
- Lockfile: A record of resolved dependency choices used to make installation more reproducible; it is not, by itself, proof that the chosen source is trusted.
- Hash check: A comparison of package bytes for integrity or tampering detection. Microsoft’s Agent Package Manager documentation says: “The
resolved_hashdetects corruption or tampering after download, but does not verify publisher identity.” - Registry or source policy: A restriction on where packages may be obtained, which can limit source redirection but does not replace inventory or integrity checks.
Microsoft’s Agent Package Manager documentation also states that its lockfile is not a standards-format SBOM. A hash match does not establish who published a package, and a source restriction does not show every package that ended up in an environment. These controls are complementary, not interchangeable. See the Agent Package Manager documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

