Quality Breakdown
85/ 200
Content Signals
Repo Health
Multi-platform bonus: +5 pts if tool supports 2+ platforms. Score derived from 12 structural signals — not stars or popularity.
Trust & Verification
medium
Requires extended permissions (shell access, subagents). Review before use.
Active
Updated within the last 90 days. Actively maintained.
Risk Assessment
- Contains install.sh script that could modify system state
- Includes .claude/ directory with skills and plugin configuration that modifies Claude environment
- CLAUDE.md file suggests persistent configuration injection into Claude runtime
- Hooks system (post_tool_use.py, session_start.py) allows injection of code execution during Claude sessions
- Cloud sync capabilities (S3, R2, D1) enable external data exfiltration
- MCP server implementation could spawn network listeners without explicit user approval