Dependency Evaluator
Evaluate npm and Python packages before adding them as dependencies. Automatically gathers package metadata, analyzes source complexity, checks security and maintenance health, and produces a structured USE / EXTRACT / BUILD verdict. Auto-triggers when your agent is about to install a new package, or run on-demand with /evaluating-dependencies <package [function]. Catches supply chain red flags like .pth injection, typosquatting, and stale maintainership.
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code
Category: Dev Tools & CI — see all ranked ›
- tashan score: 25.0
- Adoption: 1 repos
- Health: active
- GitHub stars: 0
- Contributors: 1
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · plugin:apart-tech/plugins/dependency-evaluator
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›