🔒 Zero-Trust Supply Chain Gate
greengate watch-install enforces three independent layers: (1) pre-flight static scan of postinstall scripts for network calls, eval(), process.env, and high-entropy obfuscated payloads; (2) 250ms runtime phantom-file detection; (3) post-install exec-drop detection. Catches the full spectrum of supply-chain attacks including the 2025 axios-ecosystem compromise pattern.