Install payload
Install payload is broadly covered in current results.
100% (12/12)
1 trusted · 18 review · 1 limited in this set — compare to see which signals differ.
20 results in this view
3 trust signals differ in this sample: Package trust, Source provenance, Submitter
Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
100% (12/12)
Most at-risk entries in this view
Adoption queue
2/20 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/socket-mcp-server · trust trusted · confidence 83%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/security · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/zod-audit · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
rules/ai-generated-mass-assignment-review-rules · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
rules/ai-generated-prototype-pollution-review-rules · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
rules/ai-generated-regex-safety-review-rules · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/byteray-ai-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/cve-mcp-server · trust review · confidence 67%
Decision confidence
1/20 results are low-confidence and need review before adoption.
Confident candidate for staged adoption.
74/100
mcp/socket-mcp-server · trust trusted
Address Metadata review, Package integrity before broader rollout.
54/100
commands/security · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/zod-audit · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
rules/ai-generated-mass-assignment-review-rules · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
rules/ai-generated-prototype-pollution-review-rules · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
rules/ai-generated-regex-safety-review-rules · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/byteray-ai-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/cve-mcp-server · trust review
Freshness distribution
Median age 294 days; 5 fresh of 12 scanned. Re-verify the oldest entries.
Oldest entries in this view
Security Auditor Expert - CLAUDE.md Rules for Claude Code
Not yet verified
/security - Vulnerability Scan Command for Claude Code
Not yet verified
Security Scanner Hook - Hooks
Not yet verified
Socket MCP Server for Claude
Not yet verified
Package Vulnerability Scanner - Hooks
Not yet verified
Theme distribution
70% of this view shares the top theme. Leading themes: security, vulnerability, code-review.
68 distinct themes across 20 scanned
Security analysis and vulnerability scanning for dependencies
Security intelligence MCP server that lets Claude look up CVEs, EPSS scores, CISA KEV status, OSV package vulnerabilities, exploit indicators, MITRE mappings, IP reputation, passive DNS, Shodan host data, malware intelligence, URL safety, and risk reports across optional third-party APIs.
Claude Code statusline that reads OSV-Scanner JSON results and prints a compact dependency vulnerability count for review sessions.
ByteRay MCP provides AI-augmented binary vulnerability analysis with taint tracing and zero-day hunting tools.
Source-backed rules for reviewing dependency update pull requests with supply-chain context, lockfile discipline, advisory checks, compatibility evidence, and privacy-safe metadata handling.
Comprehensive Docker image vulnerability scanning with layer analysis, base image recommendations, and security best practices enforcement. This PostToolUse hook automatically scans Docker images for vulnerabilities when Dockerfiles are modified, providing real-time security validation during development.
Expert in comprehensive production codebase analysis with Zod validation enforcement, security vulnerability detection, and code consolidation strategies
Scans for security vulnerabilities when package.json or requirements.txt files are modified.
Comprehensive security audit with vulnerability detection, threat analysis, and automated remediation recommendations
Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.
Configure Claude as a security expert for vulnerability assessment, penetration testing, and security best practices
Offensive-security MCP server from pentest-ai that lets Claude list and run wrapped security tools, plan and install missing tools, launch authorized engagements, run web, recon, API, cloud, AD, credential, vulnerability, mobile, wireless, and LLM-red-team assessments, and retrieve findings, attack chains, reports.
Apache-2.0 vulnerability scanner from Anchore for container images, filesystems, archives, SBOMs, PURLs, and CPEs, with risk scoring, VEX filtering, and CI-friendly output.
AI-powered code review specialist focusing on security vulnerabilities, OWASP Top 10, static analysis, secrets detection, and automated security best practices enforcement
Source-backed rules for reviewing AI-generated code that binds request parameters to model/entity objects before merge for mass assignment risk, covering allowlist field binding, DTOs that exclude sensitive fields, and the framework-specific autobinding features that make this easy to introduce by default.
Source-backed rules for reviewing AI-generated JavaScript/TypeScript code before merge for prototype pollution risk, covering unsafe recursive merge/clone/assign helpers on untrusted input, proto and constructor-prototype key handling, and safer alternatives like Map, Set, and Object.create(null).
Source-backed rules for reviewing AI-generated regular expressions before merge, covering catastrophic backtracking and ReDoS risk, input bounds, anchor and escaping correctness, validation versus parsing, safe engines, and privacy-safe test evidence.
Apache-2.0 security scanner from NVIDIA for AI agent skills, with static pattern checks, optional LLM semantic analysis, MCP least-privilege and tool poisoning analyzers, OSV.dev vulnerability lookups, risk scoring, and terminal, JSON, Markdown, and SARIF reports.
Offensive security MCP framework that connects AI agents to a large toolkit for authorized penetration testing, vulnerability discovery, CTF, OSINT, and security research workflows.
Production codebase auditor specialized in Zod schema validation coverage, security vulnerability detection, and dead code elimination