Install payload
Install payload is broadly covered in current results.
75% (9/12)
1 trusted · 19 review in this set — compare to see which signals differ.
20 results in this view
4 trust signals differ in this sample: Review status, Package trust, Source provenance, Submitter
Signals differ on Review status, Package trust, Source provenance — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
75% (9/12)
Adoption queue
3/20 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/socket-mcp-server · trust trusted · confidence 83%
No required blockers for this preset.
64/100
Collect package checksum or signed artifact information.
mcp/contrastapi-mcp-server · trust review · confidence 83%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/catalog-collision-scan · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/boolsai-scan-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
hooks/docker-image-security-scanner · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
statuslines/git-secrets-env-risk-statusline · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
hooks/environment-variable-leak-warning-hook · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
rules/kubernetes-devsecops-engineer · trust review · confidence 67%
Decision confidence
3/20 results are low-confidence and need review before adoption.
Confident candidate for staged adoption.
74/100
mcp/socket-mcp-server · trust trusted
Address Package integrity before broader rollout.
68/100
mcp/contrastapi-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/catalog-collision-scan · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/boolsai-scan-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
hooks/docker-image-security-scanner · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
statuslines/git-secrets-env-risk-statusline · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
hooks/environment-variable-leak-warning-hook · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
rules/kubernetes-devsecops-engineer · trust review
Freshness distribution
Median age 77 days; 6 fresh of 12 scanned. Re-verify the oldest entries.
Theme distribution
80% of this view shares the top theme. Leading themes: security, code-review, privacy.
73 distinct themes across 20 scanned
Security analysis and vulnerability scanning for dependencies
49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.
Claude Code statusline that surfaces sensitive environment-file risk and can optionally run git-secrets as a local pre-commit-style scanner.
Comprehensive Docker image vulnerability scanning with layer analysis, base image recommendations, and security best practices enforcement. This PostToolUse hook automatically scans Docker images for vulnerabilities when Dockerfiles are modified, providing real-time security validation during development.
Expert in Kubernetes DevSecOps with GitOps workflows, pod security standards, RBAC, secret management, and automated security scanning for production clusters
Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.
Scans for potential sensitive data exposure and alerts immediately.
Apache-2.0 vulnerability scanner from Anchore for container images, filesystems, archives, SBOMs, PURLs, and CPEs, with risk scoring, VEX filtering, and CI-friendly output.
Apache-2.0 CNCF-incubating Kubernetes security platform and CLI for scanning clusters, manifests, Helm charts, Kustomize projects, Git repositories, and container images for misconfigurations, compliance gaps, and vulnerabilities.
Open-source secret scanner for finding passwords, API keys, tokens, and other credentials in git history, files, directories, and stdin.
PreToolUse Write and Edit guardrail combining the hooks guide protected-file pattern with a local scan for common hardcoded credential shapes called out by GitHub secret scanning guidance before content is written.
BoolsAI hosted MCP server with no authentication required for tech stack scanning via boolsai_scan and boolsai_scan_paths tools on boolsai.ai/mcp.
MCP server for Odoo ERP systems, with tools for reading records, discovering models and fields, aggregating data, diagnosing access, scanning addons, planning migrations, and running gated safe-write workflows.
Slash command runbook for scanning HeyClaude catalog collisions by slug, title, repo URL, and docs URL before opening a content-only PR—using audit-content patterns and GitHub code search.
Secure Claude Code hooks in shared repositories: version-control hook configs, code review for PreToolUse and PostToolUse scripts, least-privilege matchers, secret scanning, and rollback when hook behavior changes.
Source-backed agent for security review of open-source pull requests, including untrusted fork boundaries, GitHub Actions permissions, secret and code scanning, dependency review, provenance signals, and maintainer-owned merge recommendations.
A source-backed collection for private research workflows: local-first planning, reproducible notebooks, local analytical processing, redaction, human review datasets, trace review, and secret scanning before outputs are shared.
Connect Claude to Semgrep — scan code for security vulnerabilities, run custom rules, inspect the AST, and pull AppSec Platform findings — with the official Semgrep Model Context Protocol server.
Offensive-security MCP server from pentest-ai that lets Claude list and run wrapped security tools, plan and install missing tools, launch authorized engagements, run web, recon, API, cloud, AD, credential, vulnerability, mobile, wireless, and LLM-red-team assessments, and retrieve findings, attack chains, reports.
A source-backed review workflow for pull requests that include AI-generated code. Treat generated diffs as untrusted implementation work, verify behavior in CI, inspect security-sensitive paths first, and merge only after a reviewer-owned checklist passes.