Skip to content

mickdownunder/safeinstall

v0.1.1MIT

Check npm packages and install dependencies through SafeInstall's artifact-bound policy gate.

MCP servers

Declared configuration, as published in mcp.json. The directory shows indexed content; it never connects to or executes these servers.

safeinstallstdio
{
  "type": "stdio",
  "command": "node",
  "args": [
    "${PLUGIN_ROOT}/scripts/run.cjs",
    "mcp"
  ]
}

What this package declares

The files a client reads when it loads this plugin, exactly as this revision carries them.

{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "safeinstall",
  "version": "0.1.1",
  "description": "Check npm packages and install dependencies through SafeInstall's artifact-bound policy gate.",
  "author": { "name": "Cyntro Systems GmbH", "email": "office@cyntro.at" },
  "homepage": "https://safeinstall.dev",
  "repository": "https://github.com/Mickdownunder/SafeInstall",
  "license": "MIT",
  "keywords": ["npm", "pnpm", "supply-chain", "security"],
  "extensions": {
    "com.openai": {
      "hooks": "./hooks/hooks.json",
      "interface": {
        "displayName": "SafeInstall",
        "shortDescription": "Package checks. Safer installs.",
        "longDescription": "Local package checks, controlled npm and pnpm installs, and project trust-surface inspection using the existing SafeInstall engine. No API key required. Review and trust the bundled hook separately to enable shell protection.",
        "developerName": "Cyntro Systems GmbH",
        "category": "Developer Tools",
        "capabilities": ["read", "write"],
        "websiteURL": "https://safeinstall.dev",
        "supportURL": "https://github.com/Mickdownunder/SafeInstall/issues",
        "defaultPrompt": ["Check this package before installing it.", "Set up SafeInstall in this project.", "Show this project's protection status."],
        "brandColor": "#16A085",
        "logo": "./assets/icon.svg",
        "composerIcon": "./assets/icon.svg"
      }
    }
  }
}

What else this package ships

These files come with the package and this site does not publish them. They are listed so you know what is there before you install it.

  • 4YAML files
View on GitHub

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • com.openai