dependency-bouncer
by Chris Dwyer · ★ 0 · updated 3 days ago
0
Vets npm and PyPI packages before they install: blocks hallucinated, typosquatted and brand-new install-script packages, flags risky ones
Install
git clone https://github.com/ccdwyer/dependency-bouncerclaude --plugin-dir ./dependency-bouncerThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
session.startcommand.runtool.call- API calls
$.clock.now$.clock.sleep$.command.register$.env.get$.fs.read$.http.fetch$.state.get$.state.set$.ui.toast- Can see
every tool call- Reach
- level 3 of 3 other: $.state.getother: $.state.setnetworkreads filesreads env varsdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/ccdwyer/dependency-bouncer
- Path in repo
- repository root
- Author
- Chris Dwyer @ccdwyer
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.