There are companies like Helix Guard scanning registries. They advertise static analysis / LLM analysis, but honeypot instances can also install packages & detect certain files like cloud configs being accessed
But relying on the goodwill of commercial sec vendors is it's own infrastructure risk.
But relying on the goodwill of commercial sec vendors is it's own infrastructure risk.