pkg-guard
pkg-guard blocks npm, pnpm, yarn, bun, pip, uv, and cargo package installs for packages that don't exist, were published in the last 30 days, or have fewer than ~100 weekly downloads—protecting against hallucinated and typosquat package names in agent workflows. It queries public registries (npmjs.org, pypi.org, crates.io) only for packages not already in your lockfile, caches results for a day, and defaults to refusing suspect installs unless explicitly approved.
Install
Source: https://github.com/MDmubarak786/claude-mods/tree/HEAD/mods/pkg-guard
What it's made of
no extra components
- Commands
- 0
- Agents
- 0
- Skills
- 0
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (MDmubarak786).