BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Claude Code Organizer (CCO)

Skill Setup & Config Recommended
Works inClaude Code
Recommended Reviewed

MCP server prompt injection is a real and underappreciated enterprise risk.

A zero-install (npx) dashboard that audits what your AI coding tool loads into context: it scans MCP servers for prompt injection, flags scope misconfigurations, tracks how much of your context-token budget each item consumes, and manages skill, memory, and hook scopes. Formerly Claude Code Organizer; now cross-harness, covering both Claude Code and Codex CLI.

357 starsMIT (commercial OK)FreeQuick setup

MCP server prompt injection is a real and underappreciated enterprise risk. CCO is the only tool combining security scanning, context optimization, and scope management — a compelling governance story for enterprise clients.

Developers and IT admins deploying Claude Code at scale who need visibility into what Claude is loading, especially teams adopting third-party MCP servers.

Claude Code Claude Cowork Claude Chat

https://github.com/mcpware/cross-code-organizer

By mcpware

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
npx @mcpware/cross-code-organizer

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me audit what tools and data Claude loads into every session
Time to functional5 minutes (no install)CostFree

Trust Signals Reviewed

Stars357Contributors1Last updated2026-06-07LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-19 · scanner v1

Community Pulse Growing

Discussed on Reddit

3 mentions across 1 sources

Reviewer notes

Reviewed review. These are observations, not a security certification.

184 stars, MIT license, zero telemetry (explicitly stated), 138 passing E2E tests, zero external dependencies. mcpware is an organization. npx zero-install model is excellent for enterprise. Provides the only integrated MCP security scanner + context auditor + scope manager. Strong candidate for every enterprise Claude Code deployment.

Zero telemetry badge and explicit privacy statement: reads only ~/.claude/ directory, no API keys accessed, no conversation content, no external data sent. Zero dependencies — strongest possible supply-chain posture. MIT license. Organization maintainer. 138 E2E tests = professional quality.

2026-04-02: LIMITATION: Pre-1.0. MCP security scanner covers known injection patterns but cannot detect novel or obfuscated prompt injection techniques.

Things to check

  • Requires npx and Node.js; dashboard visibility depends on how Claude Code is integrated into your IDE. Doesn't prevent injection at runtime, only audits configured scopes.
  • Single maintainer. Consider the risk if this person stops maintaining the project.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
5/5
Versatility
4/5
Reliability
4/5
Security
5/5
Overall score4.50 / 5.00 RecommendedEvaluatedMar 2026
184 stars, MIT license, zero telemetry (explicitly stated), 138 passing E2E tests, zero external dependencies. mcpware is an organization. npx zero-install model is excellent for enterprise. Provides the only integrated MCP security scanner + context auditor + scope manager. Strong candidate for every enterprise Claude Code deployment.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →