Evrel

No software should gain new power silently.

Evrel shows when package updates gain new capabilities like reading secrets, reaching networks, touching files, running shell commands, or loading dynamic code—with source-linked evidence. We're extending the same review to AI-authored application changes before merge.

npm package

request@2.88.2

3 capability types · 10 targets · 13 occurrences

Reads environment variables

environment.read
10 uses
environment variableHTTP_PROXY
Policy notice
lib/getProxyFromURI.js:69:7

Mutates runtime state

runtime.patch.mutate
2 uses
global memberglobalThis.exports
node_modules/jsbn/index.js:1351:5

Reads system information

system.info.read
1 use
system info fieldprocess.version
lib/helpers.js:51:17

AI made code cheaper to write and harder to approve.

Diff review was not built for machine-speed changes, behavior introduced deep in dependencies, or generated code that arrives faster than teams can understand it.

i

Detect new capabilities

See when a change adds access to environment data, files, processes, networks, browser storage, or dynamic code.

ii

Trace them to source

Trace each capability use to the exact file and location that introduced it.

iii

Compare releases

Separate added, removed, and unchanged behavior between versions.

iv

Flag what matters

Choose which modeled capabilities Evrel should call out in every report.

Join Evrel as an early partner.

We're inviting a small number of AppSec and platform security teams to use Evrel on real Node.js and TypeScript changes—and shape the evidence their reviewers need to approve or investigate them.