Metadata-Version: 2.4
Name: gqlmap
Version: 0.0.1
Summary: Inert defensive-hold placeholder for an unclaimed PyPI name referenced by a public agent skill. NOT the real gqlmap tool. Does nothing, collects nothing.
Project-URL: url, https://metano.ai/
Author-email: Metano Labs <info@metano.ai>
License: MIT
Keywords: defensive-registration,dependency-confusion,namespace-protection,placeholder
Classifier: Development Status :: 7 - Inactive
Classifier: Intended Audience :: Developers
Classifier: Topic :: Security
Requires-Python: >=3.7
Description-Content-Type: text/markdown

# `gqlmap` - defensive-hold placeholder

**This is not the real `gqlmap` tool.** It is an inert placeholder registered to prevent
dependency-confusion / skilljacking abuse of an unclaimed PyPI name that a public agent
skill instructs agents to install.

- Does nothing on install (no setup.py logic, no post-install hooks).
- Makes no network connections and collects no data.
- If imported or run, prints a notice to stderr and exits non-zero.

**Caution:** this is the *canonical* name of a real open-source tool not yet on PyPI. Prefer notifying that tool's maintainers and PyPI, and fixing the referencing skill to pin the tool's git source, over holding this name. If you publish, treat it as held-for-transfer.

- Real tool: <VERIFY canonical source before publishing - a real tool of this name exists>
- Skill that referenced the name: https://skillsmp.com/creators/shuvonsec/claude-bug-bounty/skills-graphql-audit
- Held by: `https://metano.ai` - will be transferred to the tool's maintainer or the registry on request.

Pull measurement is passive, via PyPI's public download statistics (pypistats / the
BigQuery `pypi.file_downloads` dataset). This package never reports anything itself.
