BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

safer-dependencies

Skill Security Poor
Works inClaude Code
Poor Scanned — metadata only

Reduces supply-chain attack surface and compliance violations by automatically screening dependencies for known vulnerabilities, malicious packages, and main…

safer-dependencies is a security layer for Claude Code that audits packages before they’re added to your project. It detects and fixes risky dependencies, including CVEs, typosquats, abandoned packages, version-age issues, and adds package-cooldown violations across npm, PyPI, RubyGems, Maven, Go, and Rust.

40 starsFreeQuick setup
Below standard — Significant caveats apply. Not recommended without careful review of the security and evaluation sections.

Reduces supply-chain attack surface and compliance violations by automatically screening dependencies for known vulnerabilities, malicious packages, and maintenance risks before they enter the codebase.

Engineering teams and DevSecOps leads managing multi-language projects with strict dependency governance requirements.

Claude Code Claude Cowork Claude Chat

https://github.com/robert-auger/safer-dependencies

By robert-auger

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
claude plugins install robert-auger/safer-dependencies

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.

First thing to try

After installing, paste this into Claude:

Audit npm packages before installing them in production applications
CostFree

Trust Signals Auto-scanned

Stars40Contributors2Last updated2026-08-31Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-09-19 · scanner v1

Community Pulse Growing

Discussed on Hacker News

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 35 GitHub stars; contributors unknown; last commit 1d ago; license no license.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
1/5
Versatility
2/5
Reliability
3/5
Security
3/5
Overall score2.05 / 5.00 PoorEvaluatedSep 2026
Scored from trust signals (evidence-eval-v1): 35 GitHub stars; contributors unknown; last commit 1d ago; license no license.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →