Dev.to
6/29/2026

The original title is: "Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs"
Original: Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs
Short summary
Bumblebee is an open-source supply chain scanner from Perplexity that detects compromised packages, extensions, and MCP configs across 10 ecosystems without executing code. It fills a gap traditional scanners miss: what's actually installed on a developer's machine right now, including Claude Code and IDE configs. The tool is lightweight (Go binary, zero dependencies) and safe for rapid fleet audits when supply chain advisories hit.
- •Scans 10 ecosystems (npm, PyPI, Go, RubyGems, Composer, Homebrew, MCP, VS Code, browser extensions) in seconds without executing package managers
- •Specifically designed for AI developer environments: detects compromised MCP servers and Claude Code configs that traditional scanners ignore
- •Open-source (Apache 2.0), built in Go with zero external dependencies; 4k+ GitHub stars as of v0.1.1
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



