| FMRS | 62 / 100 · C | 79 / 100 · B |
| Reliability | 9 / 20 | 12 / 20 |
|---|
| Security and permissions | 13 / 20 | 16 / 20 |
|---|
| Maintenance | 13 / 20 | 18 / 20 |
|---|
| Documentation | 14 / 20 | 18 / 20 |
|---|
| Setup experience | 13 / 20 | 15 / 20 |
| Best for | - Developers whose primary assistant is Codex, Cursor, or another non-Claude client and who want an independent Claude opinion
- Read-only, auditable code-review flows (Read/Glob/Grep access only)
- Users who want to keep context in one session and ask follow-up questions
| - Developers auditing NPM dependencies within AI workflows
- Teams performing supply chain security assessments
- Users of Claude Desktop, Cursor, or VS Code
|
| Not for | - Scenarios where Claude must edit or write to the codebase
- Users who want one registration covering all providers (Codex, Grok, Gemini, and so on) — use the unified @ask-llm/mcp package from the same repository
- Users unwilling to install and authenticate the Claude Code CLI
- Teams needing official Anthropic support or enterprise guarantees
| - Projects outside the NPM ecosystem (e.g., pure Python/Go)
- Environments without network access to deps.dev, OSV.dev, and the npm registry
- Scenarios requiring maintenance by an official upstream vendor
|
| Required permissions | - Runs locally over stdio and invokes the installed, authenticated Claude Code CLI as a subprocess
- Read-only workspace access limited to Read, Glob, and Grep
- Reads the configured environment variables (model alias, fallback model, timeout, log level)
- Sends prompts and relevant file contents to Claude
| - Network access to the NPM registry and external services (deps.dev, OSV.dev, OpenSSF, npms.io, GitHub)
- Read access to workspace lockfiles (pnpm-lock.yaml, package-lock., yarn.lock) for cache invalidation
|
| Risks and side effects | - Prompts and file contents leave the machine and are processed by Claude, so sensitive code or secrets need care
- Automatically invokes the Claude Code CLI, which may consume subscription or API quota
- The default opus model falls back to sonnet when overloaded, so results may come from a different model than expected
- Third-party, unofficial project with no affiliation with or endorsement by Anthropic
- Version 0.0.1, so interfaces and behavior may change
- get-usage-stats is in-memory only; stats are lost when the process restarts
| - Third-party READMEs and changelogs are untrusted external content; they are wrapped in tags with _meta flags but should still be handled cautiously
- Depends on availability and accuracy of external services
- Batch requests are capped at 25 packages to prevent registry enumeration; larger sets require batching
- Third-party open source project, not officially maintained by NPM or Anthropic
|
| Supported clients | Claude Code, Codex, Cursor, Claude Desktop | Claude Desktop, VS Code, Cursor |
| Tools | 3 | 19 |