# Patchloom

> Agent-safe structured edits: JSON/YAML/TOML/md/AST, dry-run, batch/tx. Not a filesystem MCP.

## Facts
- Page: https://tashan.sh/capability/pkg-patchloom
- tashan id: pkg:patchloom
- Source: https://github.com/patchloom/patchloom
- npm: https://www.npmjs.com/package/patchloom
- Type: npm
- Category: security
- tashan score: 60.0 / 100
- Adoption: 36.0
- Upkeep: 68.0
- Freshness: 92.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: deep
- npm downloads: 349/week
- License: MIT OR Apache-2.0
- Official: no

## Install

```sh
claude mcp add patchloom -- npx -y patchloom
```

## Security audit
- Known advisories: 0
- Install-time script: `node ./install.js`
- Build provenance: attested
- Declared permission surface: filesystem, network

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-09-13 by tashan (https://tashan.sh) from public evidence. Scorer s5.
