MCP
MCP servers and auth-bearing tool bridges.
HeyClaude does not publish a named validator roster yet. This page exposes the real registry coverage we can stand behind today: source status, maintainer review flags, and safety/privacy metadata completeness.
MCP servers and auth-bearing tool bridges.
Lifecycle hooks that can run local commands.
Claude Skills and capability packs.
Slash commands and command packs.
Shell/UI statusline integrations.
CLAUDE.md, AGENTS.md, editor rules, and configs.
No obvious metadata gaps in this area.
Entries needing runtime, install, file, or credential scrutiny.
Entries that should disclose data flow, credentials, logs, or third-party requests.
These tools inspect submitted metadata locally. They are review aids, not malware scanning or install approval.
Frontmatter, package references, checksum facts, submission metadata.
Server shape, package targets, placeholders, risky shell syntax, secret-like values.
Want to improve coverage? Open a focused PR that adds source-backed safety, privacy, or provenance metadata for specific entries.