# What to use for risk assessment

> 'Risk assessment' / 'threat model' — what could go wrong and what it costs.

Source: https://tashan.sh/task/risk-assessment.html
Ranked by fit for the task, then how well it documents itself, then the tashan score
  (upkeep and freshness, gated by real adoption). Public evidence only — nothing paid can
  change a rank. Method: https://tashan.sh/methodology.html

## Ranked

| # | Capability | tashan score | Adoption evidence | Activity |
|---|---|---|---|---|
| 1 | [Scf](https://tashan.sh/capability/pkg-mcp-server-scf.html) | 69 | 923/wk | active |
| 2 | [Offensive Claude](https://tashan.sh/capability/plugin-hypnguyen1209-offensive-claude-offensive-claude.html) | 62 | 326 ★ | active |
| 3 | [Langguard Scope](https://tashan.sh/capability/plugin-langguard-ai-scope-mcp-langguard-scope-mcp.html) | 43 | 5 ★ | active |
| 4 | [Clover](https://tashan.sh/capability/plugin-clover-security-clover-claude-plugin-clover.html) | 40 | 0 ★ | active |
| 5 | [Apiiro](https://tashan.sh/capability/plugin-apiiro-mcp-server-apiiro.html) | 43 | 3 ★ | active |
| 6 | [Wooyun Legacy](https://tashan.sh/capability/plugin-tanweai-wooyun-legacy-wooyun-legacy.html) | not scored | 2k ★ | abandoned |
| 7 | [Defi Guard](https://tashan.sh/capability/pkg-iniit-defi-guard-mcp.html) | 42 | 60/wk | active |
| 8 | [Ifixai](https://tashan.sh/capability/plugin-ifixai-ai-ifixai-ifixai.html) | 79 | 13k ★ | active |
| 9 | [Grc](https://tashan.sh/capability/pkg-nozomtechs-grc-mcp.html) | 63 | 239/wk | active |
| 10 | [Deadchannel](https://tashan.sh/capability/pkg-deadchannel-mcp.html) | 56 | 353/wk | active |
| 11 | [Crypto Signals](https://tashan.sh/capability/pkg-forgemeshlabs-crypto-signals-mcp.html) | 55 | 186/wk | active |
| 12 | [Walletbureau](https://tashan.sh/capability/pkg-walletbureau-mcp.html) | 50 | 152/wk | active |
| 13 | [Legal Doc Analyzer](https://tashan.sh/capability/pkg-legal-doc-analyzer.html) | 49 | 139/wk | active |
| 14 | [Trustmodel](https://tashan.sh/capability/pkg-trustmodel-mcp-server.html) | 48 | 59/wk | active |
| 15 | [Reputa](https://tashan.sh/capability/pkg-reputa-mcp.html) | 46 | 73/wk | active |
| 16 | [Mintverdict](https://tashan.sh/capability/pkg-mintverdict-mcp.html) | 44 | 75/wk | active |
| 17 | [Wallettriage](https://tashan.sh/capability/pkg-wallettriage-mcp.html) | 42 | 40/wk | active |
| 18 | [Pairbook](https://tashan.sh/capability/pkg-pairbook-mcp.html) | not scored | 778/wk | abandoned |

## What these numbers are not

- The tashan score measures upkeep, freshness and adoption. It is **not** a security
  verdict and **not** a measure of whether the capability works well.
- `not scored` means too little public evidence to rank, never that something is bad.
- The security audit is separate and free per capability, on each page above.
