‹ The Index

Dependency Evaluator

plugin

Evaluate npm and Python packages before adding them as dependencies. Automatically gathers package metadata, analyzes source complexity, checks security and maintenance health, and produces a structured USE / EXTRACT / BUILD verdict. Auto-triggers when your agent is about to install a new package, or run on-demand with /evaluating-dependencies <package [function]. Catches supply chain red flags like .pth injection, typosquatting, and stale maintainership.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Dev Tools & CI — see all ranked ›

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

source ↗  ·  plugin:apart-tech/plugins/dependency-evaluator

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›