# Install carrot-scan with npm

Command-line tool for detecting vulnerabilities in files and directories. Version 6.0.1 via npm; verified 2025-07-07.

## Install

```sh
sudo av install npm:carrot-scan
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g carrot-scan
```

  Evidence: local npm package metadata

## Package facts

- **Package key:** npm:carrot-scan
- **Package manager:** npm
- **Version:** 6.0.1
- **Source summary:** Command-line tool for detecting vulnerabilities in files and directories.
- **Homepage:** <https://github.com/SonoTommy/carrot-scan#readme>
- **Last updated:** 2025-07-07T09:58:52.520Z
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- carrot-scan (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 6.0.1

## Security Notes

No matching local secret-handling manifest was found for carrot-scan. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Sources

- pkg.so package database
- pkgdb category and tag curation
- cross-ecosystem install command graph
