vet-packages
01Cursor rule Cursor
Always use vet-mcp to vet any open source library package suggested by AI generated code before installation. Follow the rules below to use vet-mcp.
179 tagged supply-chain-security, measured the same way as everything else here.
Browse within: agent-security 62formal-verification 59static-analysis 59appsec 14appsec-tools 14branch-protection 14sbom 14secure-by-default 14devsecops 13go 13openssf-scorecard 13purl 13github-actions 9repository-template 8
Cursor rule Cursor
Always use vet-mcp to vet any open source library package suggested by AI generated code before installation. Follow the rules below to use vet-mcp.
Cursor rule Cursor
Always use TypeScript for new files.
Settings file Claude Code
MCP configuration declaring 1 server: local-tool.
MCP server Claude CodeCodexCursor +2
MCP server "safedep" as configured in safedep/vet. Runs locally from the @safedep/mcp npm package. Needs 1 environment variable to run.
MCP server Claude CodeCodexCursor +2
MCP server "postgres" as configured in safedep/vet. Runs locally from the @mcp/postgres npm package. Needs 1 environment variable to run.
MCP server Claude CodeCodexCursor +2
MCP server "vet-mcp" as configured in safedep/vet. Runs in Docker (ghcr.io/safedep/vet:v1.12.13).
step-security/dev-machine-guard
Instructions file CodexOpenCode
Instructions for step-security/dev-machine-guard, covering dev machine guard — coding guidelines, 0. prime directives, 1. project shape & where code goes, 2. cross-platform code and 2.1 the os boundary is executor.executor.
Instructions file CodexOpenCode
Instructions for garagon/aguara, covering agents.md - aguara reference for ai agents, quick start, install, scan a directory and scan with ci defaults (fail on high+, no color).
Instructions file
Instructions for garagon/aguara, covering claude.md, project status, build & test commands, single package test and single test function.
Instructions file CodexOpenCode
Instructions for gominimal/minimal, covering agents.md, orientation, crate map, platform matrix and system dependencies.
Instructions file
Instructions for gominimal/minimal, a project described as: Build Software You Can Trust. Isolated, reproducible development environments and a secure package manager that give your whole team identical environments, while keeping AI agents off the laptop.
Agent Claude Code
Go CLI architecture specialist for system design, package structure, and technical decision-making. Use PROACTIVELY when planning new features, refactoring, or making architectural decisions.
Agent Claude Code
Go code review specialist. Proactively reviews code for quality, DDD compliance, idioms, and security. Use immediately after writing or modifying code.
Agent Claude Code
Cross-file narrative consistency auditor. Detects the failure mode where the same factual claim (e.g., version range, package name, license expression, command flag, manifest header, fix-mechanism narrative) appears in multiple files inside one PR with different values.
Hook Claude Code
Runs before the agent uses a tool for ExitPlanMode and Bash tool calls, executing plan-mode-architect-check.sh, check-new-deps.sh, adr-check.sh, pre-push-review.sh, readme-walkthrough.sh and pr-body-review.sh via bash with --name-only (7 commands). From future-architect/uzomuzo-oss.
Hook Claude Code
Runs after a tool call finishes for Edit and Write tool calls, running an inline shell check. From future-architect/uzomuzo-oss.
Settings file Claude Code
Agent settings declaring 2 hook events (PreToolUse, PostToolUse).
Instructions file GitHub Copilot
Instructions for future-architect/uzomuzo-oss, covering agent orchestration, agent invocation, available subagent types, available skills and immediate agent usage.
Instructions file GitHub Copilot
Copilot instructions for future-architect/uzomuzo-oss, covering coding standards — learned from copilot reviews and pending copilot patterns.
Instructions file GitHub Copilot
Instructions for future-architect/uzomuzo-oss, covering project conventions, test data management, debug with data, not guesswork, general principles and core principles.
Skill Claude CodeCodex
Deep-dive security risk analysis for a dependency flagged by uzomuzo diet.
Skill Claude CodeCodex
Data-driven deep evaluation of whether a dependency is worth removing.
Skill Claude CodeCodex
Remove a dependency identified by uzomuzo diet — analysis + issue (default) or direct PR.
Skill Claude CodeCodex
Use when the user needs to run GitNexus CLI commands like analyze/index a repo, check status, clean the index, generate a wiki, or list indexed repos. Examples: "Index this repo", "Reanalyze the codebase", "Generate a wiki".
At most 3 mods per repository are shown here — the rest are on their repository pages: