← ClaudeAtlas

vetlisted

Run a background check on a dependency before installing it. Use when the user is considering adding a package/library and wants to know if it's safe, maintained, appropriately sized, and correctly named — or wants alternatives compared.
tokyubevoxelverse/vet · ★ 1 · AI & Automation · score 74
Install: claude install-skill tokyubevoxelverse/vet
# Vet A dependency is a hire: it gets commit access to your runtime. Before it's installed, run the background check. Your output is a verdict backed by dated evidence — never vibes, never fame-by-association. ## What to check Work through all six. Cite dates and numbers for every claim. 1. **Pulse.** Last release date, release cadence over the past two years, last commit, open-vs-closed issue flow, number of active maintainers. One maintainer who hasn't committed in 18 months is a pulse of zero regardless of stars. 2. **Weight.** Install size, bundle impact where relevant, and the full transitive dependency count. Report what the package *brings with it*, not just what it is. 3. **License.** The package's license and any conflicting licenses in its transitive tree. Flag copyleft in the tree of a commercial project loudly. 4. **Security.** Known advisories (ecosystem audit tooling, osv.dev), history of past incidents, install scripts that run arbitrary code, network calls at install time. 5. **Identity.** Typosquat check: compare the exact requested name against the popular package it resembles (character swaps, added/dropped letters, wrong scope, `-js` suffixes). Verify the registry package actually points at the repo it claims. This check has caught real attacks; take it seriously. 6. **Proportionality.** What fraction of the package would actually be used? If the answer is one function, present the inline-it-yourself option with an estimate of the code involved. ## Th