Install payload
Install payload is broadly covered in current results.
92% (11/12)
1 trusted · 24 review in this set — compare to see which signals differ.
25 results in this view
3 trust signals differ in this sample: Package trust, Source provenance, Submitter
Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
92% (11/12)
Adoption queue
2/25 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/socket-mcp-server · trust trusted · confidence 83%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/dependency-risk-review · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
guides/claude-code-subagents-for-repository-maintenance · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/claude-code-plugin-dependency-governance-capability-pack · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/codedb-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/codegraphcontext-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
guides/constraining-claude-code-plugin-dependency-versions · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
hooks/dead-code-eliminator · trust review · confidence 67%
Decision confidence
2/25 results are low-confidence and need review before adoption.
Confident candidate for staged adoption.
74/100
mcp/socket-mcp-server · trust trusted
Address Metadata review, Package integrity before broader rollout.
54/100
commands/dependency-risk-review · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
guides/claude-code-subagents-for-repository-maintenance · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/claude-code-plugin-dependency-governance-capability-pack · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/codedb-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/codegraphcontext-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
guides/constraining-claude-code-plugin-dependency-versions · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
hooks/dead-code-eliminator · trust review
Freshness distribution
Median age 54 days; 9 fresh, 3 aging or stale of 12 scanned.
Oldest entries in this view
Theme distribution
58% of this view shares the top theme. Leading themes: dependencies, security, claude-code.
78 distinct themes across 24 scanned
Security analysis and vulnerability scanning for dependencies
Code intelligence MCP server with a Zig core for local project indexing, structural outlines, symbol lookup, search, dependency graphs, snapshots, remote public-repo queries, and fallback edits.
FastAPI-native package that exposes FastAPI endpoints as Model Context Protocol tools while preserving schemas, docs, and existing authentication dependencies.
Official Snyk Studio MCP Server for connecting Claude Code, Codex CLI, Cursor, Gemini CLI, and other local MCP clients to Snyk Code, Open Source, IaC, container, SBOM, AI-BOM, package-health, authentication, and secure-at-inception workflows.
Source-backed rules for reviewing test code for test-double misuse, covering over-mocking that decouples tests from real behavior, under-mocking that creates slow or flaky tests, mock-return-value drift, missing contract tests for faked dependencies, and keeping test data free of personal information.
Guide to pinning Claude Code plugin dependency versions, semver constraints, upgrade testing, and preventing surprise behavior changes during team rollouts.
Automatically runs go mod tidy when Go files or go.mod are modified to keep dependencies clean.
Automatically checks for outdated dependencies and suggests updates with security analysis. This PostToolUse hook triggers when dependency manifest files (package.json, requirements.txt, Gemfile, go.mod, Cargo.toml, pyproject.toml) are modified, providing real-time dependency health monitoring.
Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.
Claude Code statusline that reads OSV-Scanner JSON results and prints a compact dependency vulnerability count for review sessions.
Apache-2.0 CLI and Go library from Anchore for generating SBOMs from container images, filesystems, directories, files, archives, and OCI layouts in SPDX, CycloneDX, and Syft JSON formats.
Expert Renovate review skill for evaluating dependency upgrade PRs, package rules, lockfile changes, grouping, automerge, and release readiness.
Delegate repository maintenance to Claude Code subagents: docs drift scans, dependency report triage, README sync checks, and stale issue grooming with scoped tools, read-first policies, and human merge gates.
Source-backed agent for triaging dependency update pull requests with SemVer risk, Dependabot context, GitHub dependency review, OSV advisories, OpenSSF Scorecard signals, lockfile changes, test evidence, and privacy-safe notes.
Source-backed agent that reviews Claude Code plugins for dependency and compatibility issues, checking the plugin.json manifest, bundled components, external binaries like LSP servers, versioning, and namespace conflicts, grounded in the official Claude Code plugin docs.
Source-backed rules for reviewing dependency update pull requests with supply-chain context, lockfile discipline, advisory checks, compatibility evidence, and privacy-safe metadata handling.
A Stop hook that runs npm audit, pip-audit, safety, or bundler-audit automatically at the end of every Claude Code session, detecting CVEs and outdated packages across Node.js, Python, and Ruby projects.
Scans for security vulnerabilities when package.json or requirements.txt files are modified.
Open-source platform for stateful agents with long-term memory, Letta Code local CLI agents, hosted Letta API agents, Python and TypeScript clients, skills, subagents, custom tools, MCP dependencies, and persistent agent state.
MCP server and CLI toolkit that indexes local code into a graph database so Claude can query functions, call chains, dependencies, and repository structure.
PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.
A Claude Code SessionEnd hook that scans a project for dead code and writes a report to .claude/reports. It runs available tools per language: ESLint and Knip for JS/TS, autoflake or pylint for Python, Knip for unused npm dependencies, ripgrep for unreferenced src files, and jq to flag zero-coverage files.
A CLAUDE.md rule for managing JavaScript and TypeScript monorepos. It applies Turborepo task pipelines, local and remote caching, and workspace dependency protocols — across pnpm and Nx setups — to keep cross-package builds fast and dependencies coordinated as the repository scales.
Expert Claude Claude Code plugin dependency governance capability pack for designing, reviewing, and rolling out Claude Code plugin dependency governance with source-backed checklists, production rules, and privacy-safe output contracts.
Ultra-lightweight plain text statusline with no colors or special characters for maximum compatibility and minimal overhead