safer-dependencies
Reduces supply-chain attack surface and compliance violations by automatically screening dependencies for known vulnerabilities, malicious packages, and main…
safer-dependencies is a security layer for Claude Code that audits packages before they’re added to your project. It detects and fixes risky dependencies, including CVEs, typosquats, abandoned packages, version-age issues, and adds package-cooldown violations across npm, PyPI, RubyGems, Maven, Go, and Rust.
- Ask Claude to audit npm packages before installing them in production applications.
- Generate a security report identifying known CVEs and typosquats in your Python dependencies.
- Automate detection of abandoned or outdated packages across multiple language ecosystems.
Reduces supply-chain attack surface and compliance violations by automatically screening dependencies for known vulnerabilities, malicious packages, and maintenance risks before they enter the codebase.
Engineering teams and DevSecOps leads managing multi-language projects with strict dependency governance requirements.
https://github.com/robert-auger/safer-dependencies
By robert-auger
How to Get It
claude plugins install robert-auger/safer-dependencies
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.
After installing, paste this into Claude:
Audit npm packages before installing them in production applications
Trust Signals Auto-scanned
Community Pulse Growing
Discussed on Hacker News
- Fearless FFI: Memory Safety, Safer Dependencies, Supply-Chain Attack Mitigation — Hacker News · 7 pts
- Vale's “Fearless FFI”, for Memory Safety, Safer Dependencies, and Supply-Chain — Hacker News · 5 pts
- Safer-dependencies is a security layer for Claude Code that audits dependencies — Hacker News · 1 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Scored from trust signals (evidence-eval-v1): 35 GitHub stars; contributors unknown; last commit 1d ago; license no license.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
Scored from trust signals (evidence-eval-v1): 35 GitHub stars; contributors unknown; last commit 1d ago; license no license.