dependency-bouncer

by Chris Dwyer · ★ 0 · updated 3 days ago

ToastsGuardsCommandsvalidates

0

Vets npm and PyPI packages before they install: blocks hallucinated, typosquatted and brand-new install-script packages, flags risky ones

install dependency-bouncer

Install

git clone https://github.com/ccdwyer/dependency-bouncer
claude --plugin-dir ./dependency-bouncer

Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.

View source on GitHub

What it hooks into

From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.

Events
session.startcommand.runtool.call
API calls
$.clock.now$.clock.sleep$.command.register$.env.get$.fs.read$.http.fetch$.state.get$.state.set$.ui.toast
Can see
every tool call
Reach
level 3 of 3 other: $.state.getother: $.state.setnetworkreads filesreads env varsdraws

Origin

How it got here
Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
Repository
github.com/ccdwyer/dependency-bouncer
Path in repo
repository root
Author
Chris Dwyer @ccdwyer
License
MIT
First published
Last pushed
First listed here

Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.