{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-16T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/bumblebee",
  "type": "tool",
  "slug": "bumblebee",
  "canonical_url": "https://gtmstacker.com/registry/tool/bumblebee/",
  "title": "Bumblebee",
  "description": "Apache-2.0 Go tool from Perplexity that inventories the packages and editor extensions installed on a developer machine and checks them against catalogs of known-compromised software, so a supply-chain compromise gets caught on the workstation rather than in production. It is a single static binary with zero non-stdlib dependencies, installed with `go install` and run locally; the compromised-software catalogs ship with it.",
  "category": "ai-infrastructure",
  "tags": [
    "ai-infrastructure",
    "agent-security",
    "supply-chain",
    "devsecops",
    "self-hostable"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "b7954f50364016de60bca3fad5d9fb85d9e53225190e6a06c409f1d340e23f26",
  "date_published": "2026-09-16T00:00:00Z",
  "date_modified": "2026-09-16T00:00:00Z",
  "source": {
    "name": "github · perplexityai/bumblebee",
    "url": "https://github.com/perplexityai/bumblebee"
  },
  "license": "Apache-2.0",
  "one_liner": "Bumblebee scans a dev machine's installed packages and editor extensions against known-compromised catalogs, catching supply-chain risk on the workstation.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_model": "free",
  "who_its_for": "Small teams without a security function who install a lot of open-source packages and IDE/agent extensions and want a fast local check that none of them are on a known-compromised list — especially relevant after the recent run of npm and extension supply-chain attacks.",
  "aliases": [
    "bumblebee"
  ],
  "alternatives": [
    "agentdesktop",
    "geiger"
  ],
  "secondary_categories": [
    "mcp-agents",
    "productivity-knowledge"
  ],
  "last_verified": "2026-09-16",
  "evidence": {
    "claim_type": "mixed",
    "source_id": "https://github.com/perplexityai/bumblebee",
    "note": "Apache-2.0, Go, ~5k stars, zero non-stdlib deps and the `go install` local-static-binary model confirmed on the repo (WebFetch 2026-09-16, perplexityai org). The bundled compromised-software catalogs are a vendor-side input; the scanner itself runs locally and is inspectable. Coverage is only as current as the shipped lists — read a clean result as 'nothing on the known list,' not 'proven safe.'"
  },
  "caveats": "It matches against known-compromised catalogs, so it detects what is already catalogued — it is a fast triage layer, not a guarantee, and not a replacement for a real SCA/SBOM process. Value depends on how fresh the bundled lists are; pull updates before you lean on a clean scan.",
  "lead": "Apache-2.0 Go tool from Perplexity that inventories the packages and editor/agent extensions on a developer machine and checks them against catalogs of known-compromised software, moving supply-chain detection to the workstation instead of waiting for it to reach production. It ships as a single static binary with zero non-stdlib dependencies, installs…",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 110,
      "text": "Apache-2.0 Go tool from Perplexity that inventories the packages and editor/agent extensions on a developer machine and checks them against catalogs of known-compromised software, moving supply-chain detection to the workstation instead of waiting for it to reach production. It ships as a single static binary with zero non-stdlib dependencies, installs with `go install`, and runs locally; the compromised-software catalogs are bundled."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 235,
      "text": "extensions on a developer machine and checks them against catalogs of known-compromised software, moving supply-chain detection to the workstation instead of waiting for it to reach production. It ships as a single static binary with zero non-stdlib dependencies, installs with `go install`, and runs locally; the compromised-software catalogs are bundled.\n\n- Apache-2.0, Go, ~5k stars, zero non-stdlib dependencies and the `go install` / local-static-binary model independently WebFetch-verified on the repo 2026-09-16 (github.com/perplexityai/bumblebee, published under the perplexityai org).\n- Surfaced via the 2026-09-16 viral-posts brief (a \"5 repos about to blow up\" drop naming Bumblebee for MCP-security workflows); its inclusion here is on the verified repo facts, not the listicle framing.\n- Curated from the GTM Stacker signal registry (2026-09-16 pass: daily pull + viral-posts brief); license independently verified 2026-09-16."
    },
    {
      "index": 2,
      "heading_path": [
        null,
        "Why it matters for a GTM stack"
      ],
      "est_tokens": 265,
      "text": "via the 2026-09-16 viral-posts brief (a \"5 repos about to blow up\" drop naming Bumblebee for MCP-security workflows); its inclusion here is on the verified repo facts, not the listicle framing. - Curated from the GTM Stacker signal registry (2026-09-16 pass: daily pull + viral-posts brief); license independently verified 2026-09-16.\n\nThe GTM stack is now half open-source packages and half IDE and agent extensions, and the last few months have shown how a single poisoned npm package or editor extension quietly turns into stolen tokens. Bumblebee is the cheap, local first check: point it at a machine, get back a list of anything on it that matches a known-compromised catalog. For a team without a security hire, that is a real gap filled with one static binary and no service to run. The honest read is that it only knows what is catalogued — so it is triage, not proof of safety — and its usefulness tracks how current the bundled lists are. As a workstation-level tripwire for the supply-chain attacks this registry keeps flagging, it earns its place."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/bumblebee/index.md",
    "html": "https://gtmstacker.com/registry/tool/bumblebee/",
    "json": "https://gtmstacker.com/registry/tool/bumblebee/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/bumblebee/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/bumblebee/#software",
        "name": "Bumblebee",
        "identifier": "io.github.perplexityai/bumblebee",
        "description": "Apache-2.0 Go tool from Perplexity that inventories the packages and editor extensions installed on a developer machine and checks them against catalogs of known-compromised software, so a supply-chain compromise gets caught on the workstation rather than in production. It is a single static binary with zero non-stdlib dependencies, installed with `go install` and run locally; the compromised-software catalogs ship with it.",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/bumblebee/",
        "datePublished": "2026-09-16T00:00:00Z",
        "dateModified": "2026-09-16T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "license": "https://spdx.org/licenses/Apache-2.0.html",
        "codeRepository": "https://github.com/perplexityai/bumblebee",
        "keywords": "ai-infrastructure, mcp-agents, productivity-knowledge, agent-security, supply-chain, devsecops, self-hostable",
        "author": {
          "@type": "Organization",
          "name": "perplexityai",
          "url": "https://github.com/perplexityai",
          "sameAs": [
            "https://github.com/perplexityai/bumblebee"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "agentdesktop",
            "url": "https://gtmstacker.com/registry/tool/agentdesktop/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Geiger",
            "url": "https://gtmstacker.com/registry/tool/geiger/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/bumblebee/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "AI Infrastructure",
            "item": "https://gtmstacker.com/registry/category/ai-infrastructure/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Bumblebee",
            "item": "https://gtmstacker.com/registry/tool/bumblebee/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "io.github.perplexityai/bumblebee",
    "repository": {
      "url": "https://github.com/perplexityai/bumblebee",
      "source": "github"
    }
  }
}
