Skip to main content

Browse the directory

Showing 25 resources for "dependencies"
Saved
Active

1 trusted · 24 review in this set — compare to see which signals differ.

Trust snapshot

25 results in this view

Claimed
0%(0/25)

3 trust signals differ in this sample: Package trust, Source provenance, Submitter

Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

92% (11/12)

Adoption queue

Browse adoption queue · balanced

2/25 visible results are in hold tier and need mitigation before adoption.

ready 0caution 23hold 2

Socket MCP Server for Claude

1 blockers: Metadata review

caution

70/100

Request metadata review from maintainers or internal owners.

mcp/socket-mcp-server · trust trusted · confidence 83%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

guides/claude-code-subagents-for-repository-maintenance · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/claude-code-plugin-dependency-governance-capability-pack · trust review · confidence 67%

CodeDB MCP Server

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/codedb-mcp-server · trust review · confidence 67%

CodeGraphContext MCP Server

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/codegraphcontext-mcp-server · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

guides/constraining-claude-code-plugin-dependency-versions · trust review · confidence 67%

Dead Code Eliminator - Hooks

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/dead-code-eliminator · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

2/25 results are low-confidence and need review before adoption.

high 1medium 22low 2

Socket MCP Server for Claude

Confident candidate for staged adoption.

high

74/100

Missing: Metadata review

mcp/socket-mcp-server · trust trusted

Claude Code Subagents For Repository Maintenance

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

guides/claude-code-subagents-for-repository-maintenance · trust review

CodeDB MCP Server

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/codedb-mcp-server · trust review

CodeGraphContext MCP Server

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/codegraphcontext-mcp-server · trust review

Dead Code Eliminator - Hooks

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/dead-code-eliminator · trust review

Freshness distribution

Mostly fresh with a few aging entries

Median age 54 days; 9 fresh, 3 aging or stale of 12 scanned.

median 54d

Aging

91–180 days

0%

0 entries

Stale

> 180 days

25%

3 entries

Theme distribution

Results center on dependencies

58% of this view shares the top theme. Leading themes: dependencies, security, claude-code.

Focused

78 distinct themes across 24 scanned

CodeDB logo

Code intelligence MCP server with a Zig core for local project indexing, structural outlines, symbol lookup, search, dependency graphs, snapshots, remote public-repo queries, and fallback edits.

FastAPI-MCP logo

FastAPI-native package that exposes FastAPI endpoints as Model Context Protocol tools while preserving schemas, docs, and existing authentication dependencies.

Official Snyk Studio MCP Server for connecting Claude Code, Codex CLI, Cursor, Gemini CLI, and other local MCP clients to Snyk Code, Open Source, IaC, container, SBOM, AI-BOM, package-health, authentication, and secure-at-inception workflows.

Source-backed rules for reviewing test code for test-double misuse, covering over-mocking that decouples tests from real behavior, under-mocking that creates slow or flaky tests, mock-return-value drift, missing contract tests for faked dependencies, and keeping test data free of personal information.

Guide to pinning Claude Code plugin dependency versions, semver constraints, upgrade testing, and preventing surprise behavior changes during team rollouts.

Automatically runs go mod tidy when Go files or go.mod are modified to keep dependencies clean.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Automatically checks for outdated dependencies and suggests updates with security analysis. This PostToolUse hook triggers when dependency manifest files (package.json, requirements.txt, Gemfile, go.mod, Cargo.toml, pyproject.toml) are modified, providing real-time dependency health monitoring.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.

Invocation:/dependency-risk-review [package]
Safety ✓ Privacy ✓

Claude Code statusline that reads OSV-Scanner JSON results and prints a compact dependency vulnerability count for review sessions.

Syft logo
Syftby Anchore · submitted by oktofeesh1

Apache-2.0 CLI and Go library from Anchore for generating SBOMs from container images, filesystems, directories, files, archives, and OCI layouts in SPDX, CycloneDX, and Syft JSON formats.

Expert Renovate review skill for evaluating dependency upgrade PRs, package rules, lockfile changes, grouping, automerge, and release readiness.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Delegate repository maintenance to Claude Code subagents: docs drift scans, dependency report triage, README sync checks, and stale issue grooming with scoped tools, read-first policies, and human merge gates.

Source-backed agent for triaging dependency update pull requests with SemVer risk, Dependabot context, GitHub dependency review, OSV advisories, OpenSSF Scorecard signals, lockfile changes, test evidence, and privacy-safe notes.

Source-backed agent that reviews Claude Code plugins for dependency and compatibility issues, checking the plugin.json manifest, bundled components, external binaries like LSP servers, versioning, and namespace conflicts, grounded in the official Claude Code plugin docs.

Source-backed rules for reviewing dependency update pull requests with supply-chain context, lockfile discipline, advisory checks, compatibility evidence, and privacy-safe metadata handling.

A Stop hook that runs npm audit, pip-audit, safety, or bundler-audit automatically at the end of every Claude Code session, detecting CVEs and outdated packages across Node.js, Python, and Ruby projects.

Scans for security vulnerabilities when package.json or requirements.txt files are modified.

Trigger:PostToolUse
Safety ✓ Privacy ✓
Letta logo

Open-source platform for stateful agents with long-term memory, Letta Code local CLI agents, hosted Letta API agents, Python and TypeScript clients, skills, subagents, custom tools, MCP dependencies, and persistent agent state.

MCP server and CLI toolkit that indexes local code into a graph database so Claude can query functions, call chains, dependencies, and repository structure.

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓

A Claude Code SessionEnd hook that scans a project for dead code and writes a report to .claude/reports. It runs available tools per language: ESLint and Knip for JS/TS, autoflake or pylint for Python, Knip for unused npm dependencies, ripgrep for unreferenced src files, and jq to flag zero-coverage files.

A CLAUDE.md rule for managing JavaScript and TypeScript monorepos. It applies Turborepo task pipelines, local and remote caching, and workspace dependency protocols — across pnpm and Nx setups — to keep cross-package builds fast and dependencies coordinated as the repository scales.

Safety · Privacy ·

Expert Claude Claude Code plugin dependency governance capability pack for designing, reviewing, and rolling out Claude Code plugin dependency governance with source-backed checklists, production rules, and privacy-safe output contracts.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Ultra-lightweight plain text statusline with no colors or special characters for maximum compatibility and minimal overhead