Skip to main content

Browse the directory

Showing 2 resources for "checksums"
Saved
Active

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

2 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (2/2)

Adoption queue

Browse adoption queue · balanced

0/2 visible results are ready for staged adoption under this preset.

ready 0caution 2hold 0
caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/package-download-checksum-guard-hook · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

guides/package-provenance-checks-before-installing-mcp-servers · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

0/2 results are high-confidence for the selected preset.

high 0medium 2low 0

Freshness distribution

Current results are broadly fresh

Median age 41 days; all 2 scanned entries are within 90 days.

median 41d

Aging

91–180 days

0%

0 entries

Stale

> 180 days

0%

0 entries

PreToolUse hook that reviews proposed Bash commands for package, installer, and archive downloads, then blocks curl or wget download commands that do not include an adjacent checksum or signature verification step.

Trigger:PreToolUse
Safety ✓ Privacy ✓

Verify MCP server package provenance before Claude Code installation: registry publisher match, repository ownership, release artifact checksums, maintainer history, and rollback when supply-chain signals fail review.