Appearance
External Validation Report
Third checked-in external validation summary for
lintaiafter broader-mix precision evidence hardening. Cohort source of truth lives in validation/external-repos/repo-shortlist.toml, current results in validation/external-repos/ledger.toml, and wave 2 baseline in validation/external-repos/archive/wave2-ledger.toml.
Cohort Composition
The current cohort still contains 48 public repositories:
20mcp-focused repos12cursor_plugin-focused repos16skills-focused repos
Overall Counts
Current checked-in wave 3 results:
48repos evaluated2199total findings1059stable findings1140preview findings2runtime parser errors40diagnostics
Recommended Counts By Tier
- stable findings:
17 - preview findings:
27
Supply-Chain Counts By Tier
- stable findings:
132 - preview findings:
94
Cohort Ownership Split
- total official repos:
20 - total community repos:
28
Recommended Stable By Ownership
- official
recommended stablehit count:10 - community
recommended stablehit count:7
Zero-Hit Coverage By Ownership
- official repos with
0recommended stablehits:17 - community repos with
0recommended stablehits:21
Remaining Non-Default Lane Totals
base:23stable,0previewclaude:19stable,27previewmcp:20stable,0previewpreview:904stable,1046previewskills:888stable,1019preview
Hybrid Scope Expansion Results
Current wave inventory for the newly expanded JSON lanes:
- repos with root
mcp.json:6 - repos with
.mcp.json:10 - repos with
.cursor/mcp.json:0 - repos with
.vscode/mcp.json:0 - repos with
.roo/mcp.json:1 - repos with
.kiro/settings/mcp.json:1 - repos with
gemini-extension.json:2 - repos with
gemini.settings.json:1 - repos with
.gemini/settings.json:0 - repos with
vscode.settings.json:0 - repos with
.claude/mcp/*.json:1 - repos with Docker-based MCP launch configs:
3 - MCP findings from expanded client-config coverage (
SEC301-SEC331,SEC337-SEC339,SEC346):13 - findings from
SEC336:0 - findings from
SEC337-SEC339,SEC346:3 - AI-native markdown preview findings:
SEC313fenced pipe-to-shell examples:4SEC335metadata-service access examples:1SEC347mutable MCP setup launcher examples:9- CLI-form repo hits:
1 - config-snippet-form repo hits:
9
- CLI-form repo hits:
SEC348mutable Docker registry-image examples:5SEC349Docker host-escape or privileged runtime examples:2SEC350untrusted-input instruction-promotion examples:0SEC351approval-bypass instruction examples:4SEC352unscoped Bash tool grants in frontmatter:7SEC353Copilot instruction files above 4000 chars:0SEC354path-specific Copilot instructions missingapplyTo:0SEC355wildcard tool grants in frontmatter:0SEC356plugin agent frontmatterpermissionMode:0SEC357plugin agent frontmatterhooks:0SEC358plugin agent frontmattermcpServers:0SEC359Cursor rule non-booleanalwaysApply:0SEC360Cursor rule non-sequenceglobs:2SEC361Claude settings missing$schema:6SEC362Claude settings wildcardBash(*)permissions:1SEC363Claude settings home-directory hook commands:1SEC364Claude settingsbypassPermissionsdefault mode:0SEC365Claude settings non-HTTPSallowedHttpHookUrls:0SEC366Claude settings dangerous host literals inallowedHttpHookUrls:0SEC367Claude settings wildcardWebFetch(*)permissions:1SEC368Claude settings repo-external absolute hook paths:0SEC369Claude settings wildcardWrite(*)permissions:1SEC370path-specific Copilot instructions using the wrong suffix:0SEC371path-specific Copilot instructions with invalidapplyTo:0SEC377path-specific Copilot instructions with invalidapplyToglobs:0SEC378Cursor rules with redundantglobsalongsidealwaysApply: true:2SEC379Cursor rules with unknown frontmatter keys:0SEC380Cursor rules missingdescription:2SEC381Claude settings command hooks missingtimeout:4SEC382Claude settingsmatcheron unsupported hook events:4SEC383Claude settings missingmatcheron matcher-capable hook events:0SEC384Claude settings bareWebSearchpermissions:2SEC385Claude settings sharedgit pushpermissions:1SEC386Claude settings sharedgit checkout:*permissions:1SEC387Claude settings sharedgit commit:*permissions:1SEC388Claude settings sharedgit stash:*permissions:1SEC394MCP configs with wildcardautoApprove:0SEC395MCP configs withautoApproveTools: true:0SEC396MCP configs withtrustTools: true:0SEC397MCP configs with sandbox disabled:0SEC398MCP configs with wildcard capabilities:0SEC399Claude settings sharedBash(npx ...)permissions:1SEC400Claude settings sharedenabledMcpjsonServers:2SEC405Claude settings shared package installation permissions:0SEC406Claude settings sharedgit addpermissions:1SEC407Claude settings sharedgit clonepermissions:1SEC408Claude settings sharedgh prpermissions:0SEC502Claude settings sharedgh api --method POSTpermissions:0SEC503Claude settings sharedgh issue createpermissions:0SEC504Claude settings sharedgh repo createpermissions:0SEC508Claude settings sharedgh secret setpermissions:0SEC509Claude settings sharedgh variable setpermissions:0SEC510Claude settings sharedgh workflow runpermissions:0SEC514Claude settings sharedgh secret deletepermissions:0SEC515Claude settings sharedgh variable deletepermissions:0SEC516Claude settings sharedgh workflow disablepermissions:0SEC409Claude settings sharedgit fetchpermissions:1SEC410Claude settings sharedgit ls-remotepermissions:1SEC411Claude settings sharedcurlpermissions:1SEC412Claude settings sharedwgetpermissions:0SEC413Claude settings sharedgit configpermissions:1SEC414Claude settings sharedgit tagpermissions:1SEC415Claude settings sharedgit branchpermissions:1SEC416AI-native markdown barepip installClaude transcripts:0SEC417AI-native markdown unpinnedpip install git+https://...examples:2SEC418Claude settings raw GitHub content fetch permissions:1SEC474AI-native markdown sharedgh prtool grants:0SEC475Claude settings unsafeRead(...)path permissions:0SEC476Claude settings unsafeWrite(...)path permissions:0SEC477Claude settings unsafeEdit(...)path permissions:0SEC478Claude settings sharedgit reset:*permissions:0SEC479Claude settings sharedgit clean:*permissions:0SEC480Claude settings sharedgit restore:*permissions:0SEC481Claude settings sharedgit rebase:*permissions:0SEC482Claude settings sharedgit merge:*permissions:0SEC483Claude settings sharedgit cherry-pick:*permissions:1SEC484Claude settings sharedgit apply:*permissions:0SEC485Claude settings sharedgit am:*permissions:0SEC486Claude settings unsafeGlob(...)path permissions:0SEC487Claude settings unsafeGrep(...)path permissions:0SEC488Claude settings sharedBash(uvx ...)permissions:0SEC489Claude settings sharedBash(pnpm dlx ...)permissions:0SEC490Claude settings sharedBash(yarn dlx ...)permissions:0SEC491Claude settings sharedBash(pipx run ...)permissions:0SEC492Claude settings sharedBash(npm exec ...)permissions:0SEC493Claude settings sharedBash(bunx ...)permissions:0SEC494AI-native markdown sharednpm exectool grants:0SEC495AI-native markdown sharedbunxtool grants:0SEC496AI-native markdown shareduvxtool grants:0SEC497AI-native markdown sharedpnpm dlxtool grants:0SEC498AI-native markdown sharedyarn dlxtool grants:0SEC499AI-native markdown sharedpipx runtool grants:0SEC500AI-native markdown sharednpxtool grants:0SEC501AI-native markdown sharedgit ls-remotetool grants:0SEC505AI-native markdown sharedgh api --method POSTtool grants:0SEC506AI-native markdown sharedgh issue createtool grants:0SEC507AI-native markdown sharedgh repo createtool grants:0SEC511AI-native markdown sharedgh secret settool grants:0SEC512AI-native markdown sharedgh variable settool grants:0SEC513AI-native markdown sharedgh workflow runtool grants:0SEC517AI-native markdown sharedgh secret deletetool grants:0SEC518AI-native markdown sharedgh variable deletetool grants:0SEC519AI-native markdown sharedgh workflow disabletool grants:0SEC372Claude settings wildcardRead(*)permissions:1SEC373Claude settings wildcardEdit(*)permissions:1SEC374Claude settings wildcardWebSearch(*)permissions:1SEC375Claude settings wildcardGlob(*)permissions:1SEC376Claude settings wildcardGrep(*)permissions:1- current
SEC347usefulness is being driven mainly by MCP config snippets
- repos with
tool_descriptor_json:10 - findings from
SEC314-SEC318:0 - repos where new MCP client-config variants existed only under fixture-like paths:
1 - repos where Docker-based MCP launch existed only under fixture-like client-config variants:
0 - no non-fixture external
Stablehits were produced yet on committed tool-descriptor JSON SEC348repo-level preview hits on the canonical cohort:jeremylongshore/claude-code-plugins-plus-skills:1preview finding(s) viaSEC348giuseppe-trisciuoglio/developer-kit-claude-code:1preview finding(s) viaSEC348zebbern/claude-code-guide:1preview finding(s) viaSEC348zechenzhangAGI/AI-research-SKILLs:1preview finding(s) viaSEC348trailofbits/skills:1preview finding(s) viaSEC348
SEC349repo-level preview hits on the canonical cohort:zechenzhangAGI/AI-research-SKILLs:1preview finding(s) viaSEC349trailofbits/skills:1preview finding(s) viaSEC349
SEC350produced no repo-level preview hits yet on the canonical cohortSEC351repo-level preview hits on the canonical cohort:jeremylongshore/claude-code-plugins-plus-skills:1preview finding(s) viaSEC351agent-sh/agentsys:1preview finding(s) viaSEC351zechenzhangAGI/AI-research-SKILLs:1preview finding(s) viaSEC351buildingopen/claude-setup:1preview finding(s) viaSEC351
SEC352produced no repo-level preview hits yet on the canonical cohortSEC353produced no repo-level preview hits yet on the canonical cohortSEC354produced no repo-level preview hits yet on the canonical cohortSEC355produced no repo-level preview hits yet on the canonical cohortSEC356produced no repo-level preview hits yet on the canonical cohortSEC357produced no repo-level preview hits yet on the canonical cohortSEC358produced no repo-level preview hits yet on the canonical cohortSEC359produced no repo-level preview hits yet on the canonical cohortSEC360repo-level preview hits on the canonical cohort:TencentCloudBase/CloudBase-MCP:1preview finding(s) viaSEC360blockscout/mcp-server:1preview finding(s) viaSEC360
SEC361repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC361centminmod/my-claude-code-setup:1preview finding(s) viaSEC361TencentCloudBase/CloudBase-MCP:1preview finding(s) viaSEC361blockscout/mcp-server:1preview finding(s) viaSEC361agent-sh/agentsys:1preview finding(s) viaSEC361buildingopen/claude-setup:1preview finding(s) viaSEC361
SEC362produced no repo-level preview hits yet on the canonical cohortSEC363repo-level preview hits on the canonical cohort:buildingopen/claude-setup:1preview finding(s) viaSEC363
SEC364produced no repo-level preview hits yet on the canonical cohortSEC365produced no repo-level preview hits yet on the canonical cohortSEC366produced no repo-level preview hits yet on the canonical cohortSEC367produced no repo-level preview hits yet on the canonical cohortSEC368produced no repo-level preview hits yet on the canonical cohortSEC369produced no repo-level preview hits yet on the canonical cohortSEC370produced no repo-level preview hits yet on the canonical cohortSEC371produced no repo-level preview hits yet on the canonical cohortSEC372produced no repo-level preview hits yet on the canonical cohortSEC373produced no repo-level preview hits yet on the canonical cohortSEC374produced no repo-level preview hits yet on the canonical cohortSEC375produced no repo-level preview hits yet on the canonical cohortSEC376produced no repo-level preview hits yet on the canonical cohortSEC377produced no repo-level preview hits yet on the canonical cohortSEC378repo-level preview hits on the canonical cohort:blockscout/mcp-server:1preview finding(s) viaSEC378get-convex/convex-agent-plugins:1preview finding(s) viaSEC378
SEC379produced no repo-level preview hits yet on the canonical cohortSEC380repo-level preview hits on the canonical cohort:TencentCloudBase/CloudBase-MCP:1preview finding(s) viaSEC380blockscout/mcp-server:1preview finding(s) viaSEC380
SEC381repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC381centminmod/my-claude-code-setup:1preview finding(s) viaSEC381blockscout/mcp-server:1preview finding(s) viaSEC381buildingopen/claude-setup:1preview finding(s) viaSEC381
SEC382repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC382centminmod/my-claude-code-setup:1preview finding(s) viaSEC382blockscout/mcp-server:1preview finding(s) viaSEC382buildingopen/claude-setup:1preview finding(s) viaSEC382
SEC383produced no repo-level preview hits yet on the canonical cohortSEC384produced no repo-level preview hits yet on the canonical cohortSEC385repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC385
SEC386repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC386
SEC387repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC387
SEC388repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC388
SEC399repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC399
SEC400produced no repo-level preview hits yet on the canonical cohortSEC405produced no repo-level preview hits yet on the canonical cohortSEC406repo-level preview hits on the canonical cohort:airmcp-com/mcp-standards:1preview finding(s) viaSEC406
SEC407repo-level preview hits on the canonical cohort:blockscout/mcp-server:1preview finding(s) viaSEC407
SEC408produced no repo-level preview hits yet on the canonical cohortSEC502produced no repo-level preview hits yet on the canonical cohortSEC503produced no repo-level preview hits yet on the canonical cohortSEC504produced no repo-level preview hits yet on the canonical cohortSEC508produced no repo-level preview hits yet on the canonical cohortSEC509produced no repo-level preview hits yet on the canonical cohortSEC510produced no repo-level preview hits yet on the canonical cohortSEC514produced no repo-level preview hits yet on the canonical cohortSEC515produced no repo-level preview hits yet on the canonical cohortSEC516produced no repo-level preview hits yet on the canonical cohortSEC409repo-level preview hits on the canonical cohort:blockscout/mcp-server:1preview finding(s) viaSEC409
SEC410repo-level preview hits on the canonical cohort:blockscout/mcp-server:1preview finding(s) viaSEC410
SEC411produced no repo-level preview hits yet on the canonical cohortSEC412produced no repo-level preview hits yet on the canonical cohortSEC413produced no repo-level preview hits yet on the canonical cohortSEC414produced no repo-level preview hits yet on the canonical cohortSEC415produced no repo-level preview hits yet on the canonical cohortSEC416produced no repo-level preview hits yet on the canonical cohortSEC417produced no repo-level preview hits yet on the canonical cohortSEC418produced no repo-level preview hits yet on the canonical cohortSEC474produced no repo-level preview hits yet on the canonical cohortSEC475produced no repo-level preview hits yet on the canonical cohortSEC476produced no repo-level preview hits yet on the canonical cohortSEC477produced no repo-level preview hits yet on the canonical cohortSEC478produced no repo-level preview hits yet on the canonical cohortSEC479produced no repo-level preview hits yet on the canonical cohortSEC480produced no repo-level preview hits yet on the canonical cohortSEC481produced no repo-level preview hits yet on the canonical cohortSEC482produced no repo-level preview hits yet on the canonical cohortSEC483repo-level preview hits on the canonical cohort:centminmod/my-claude-code-setup:1preview finding(s) viaSEC483
SEC484produced no repo-level preview hits yet on the canonical cohortSEC485produced no repo-level preview hits yet on the canonical cohortSEC486produced no repo-level preview hits yet on the canonical cohortSEC487produced no repo-level preview hits yet on the canonical cohortSEC488produced no repo-level preview hits yet on the canonical cohortSEC489produced no repo-level preview hits yet on the canonical cohortSEC490produced no repo-level preview hits yet on the canonical cohortSEC491produced no repo-level preview hits yet on the canonical cohortSEC492produced no repo-level preview hits yet on the canonical cohortSEC493produced no repo-level preview hits yet on the canonical cohortSEC494produced no repo-level preview hits yet on the canonical cohortSEC495produced no repo-level preview hits yet on the canonical cohortSEC496produced no repo-level preview hits yet on the canonical cohortSEC497produced no repo-level preview hits yet on the canonical cohortSEC498produced no repo-level preview hits yet on the canonical cohortSEC499produced no repo-level preview hits yet on the canonical cohortSEC500produced no repo-level preview hits yet on the canonical cohortSEC501produced no repo-level preview hits yet on the canonical cohortSEC505produced no repo-level preview hits yet on the canonical cohortSEC506produced no repo-level preview hits yet on the canonical cohortSEC507produced no repo-level preview hits yet on the canonical cohortSEC511produced no repo-level preview hits yet on the canonical cohortSEC512produced no repo-level preview hits yet on the canonical cohortSEC513produced no repo-level preview hits yet on the canonical cohortSEC517produced no repo-level preview hits yet on the canonical cohortSEC518produced no repo-level preview hits yet on the canonical cohortSEC519produced no repo-level preview hits yet on the canonical cohortSEC394produced no repo-level stable hits yet on the canonical cohortSEC395produced no repo-level stable hits yet on the canonical cohortSEC396produced no repo-level stable hits yet on the canonical cohortSEC397produced no repo-level stable hits yet on the canonical cohortSEC398produced no repo-level stable hits yet on the canonical cohort- fixture/testdata/example suppression stayed active for the newly added MCP client-config variants and did not create a fake usefulness signal from fixture-like paths
Delta From Previous Wave
- stable findings:
75->1059 - preview findings:
86->1140 - runtime parser errors:
0->2 - diagnostics:
4->40 - repo verdict changes: none
Adjudication Coverage For Recommended Stable
- recommended stable findings:
17 - adjudicated hits:
17 - unadjudicated hits:
0 - adjudicated false positives:
0
Reviewed Recommended Stable Hits
TencentCloudBase/CloudBase-MCP:SEC329at.mcp.json-confirmed_issue- committed MCP config launches through npx reason:.mcp.jsonusescommand: "npx"with@cloudbase/cloudbase-mcp@latestin committed MCP server config. problem: mutable package launcher in committed MCP configTencentCloudBase/CloudBase-MCP:SEC329atconfig/source/editor-config/files/gemini.settings.json-confirmed_issue- committed MCP config launches through npx reason:config/source/editor-config/files/gemini.settings.jsonusescommand: "npx"with mutablenpm-global-exec@latestand@cloudbase/cloudbase-mcp@latest. problem: mutable package launcher in committed MCP configTencentCloudBase/CloudBase-MCP:SEC329atgemini-extension.json-confirmed_issue- committed MCP config launches through npx reason:gemini-extension.jsonusescommand: "npx"with mutablenpm-global-exec@latestand@cloudbase/cloudbase-mcp@latest. problem: mutable package launcher in committed MCP configTencentCloudBase/CloudBase-MCP:SEC329atmcp/.mcp.json-confirmed_issue- committed MCP config launches through npx reason:mcp/.mcp.jsonusescommand: "npx"with mutablenpm-global-exec@latestand@cloudbase/cloudbase-mcp@latest. problem: mutable package launcher in committed MCP configTencentCloudBase/CloudBase-MCP:SEC329atmcp/mcp.json-confirmed_issue- committed MCP config launches through npx reason:mcp/mcp.jsonusescommand: "npx"with mutablenpm-global-exec@latestand@cloudbase/cloudbase-mcp@latest. problem: mutable package launcher in committed MCP configaffaan-m/everything-claude-code:SEC329at.mcp.json-confirmed_issue- committed MCP config launches through npx reason:.mcp.jsonuses committednpxlaunchers for multiple MCP servers including@modelcontextprotocol/server-github,@upstash/context7-mcp, and@playwright/mcp. problem: mutable package launcher in committed MCP configairmcp-com/mcp-standards:SEC340at.claude/settings.json-confirmed_issue- committed Claude hook executes through npx reason:.claude/settings.jsoncontains committed command hooks invokingnpx claude-flow@alpha .... problem: mutable package launcher in committed Claude hook configalirezarezvani/claude-skills:SEC329atengineering-team/playwright-pro/.mcp.json-confirmed_issue- committed MCP config launches through npx reason:engineering-team/playwright-pro/.mcp.jsonusescommand: "npx"to run committedtsx-based MCP integrations. problem: mutable package launcher in committed MCP configanthropics/claude-plugins-official:SEC329atexternal_plugins/context7/.mcp.json-confirmed_issue- committed MCP config launches through mutable package runner reason:external_plugins/context7/.mcp.jsonusescommand: "npx"with@upstash/context7-mcpin committed plugin MCP config. problem: mutable package launcher in committed MCP configanthropics/claude-plugins-official:SEC329atexternal_plugins/firebase/.mcp.json-confirmed_issue- committed MCP config launches through mutable package runner reason:external_plugins/firebase/.mcp.jsonusescommand: "npx"with mutablefirebase-tools@latest mcp. problem: mutable package launcher in committed MCP configanthropics/claude-plugins-official:SEC329atexternal_plugins/playwright/.mcp.json-confirmed_issue- committed MCP config launches through mutable package runner reason:external_plugins/playwright/.mcp.jsonusescommand: "npx"with@playwright/mcp@latestin committed plugin MCP config. problem: mutable package launcher in committed MCP configanthropics/claude-plugins-official:SEC329atexternal_plugins/serena/.mcp.json-confirmed_issue- committed MCP config launches through mutable package runner reason:external_plugins/serena/.mcp.jsonusescommand: "uvx"withgit+https://github.com/oraios/serenain committed plugin MCP config. problem: mutable package launcher in committed MCP configbuildingopen/claude-setup:SEC329atclaude/.mcp.json-confirmed_issue- committed MCP config launches through npx reason:claude/.mcp.jsonusescommand: "npx"with-y session-recall --mcpin committed MCP server config. problem: mutable package launcher in committed MCP configcentminmod/my-claude-code-setup:SEC329at.claude/mcp/chrome-devtools.json-confirmed_issue- committed MCP config launches through npx reason:.claude/mcp/chrome-devtools.jsonsetscommand: "npx"withchrome-devtools-mcp@latest. problem: mutable package launcher in committed MCP configget-convex/convex-agent-plugins:SEC329atmcp.json-confirmed_issue- committed MCP config launches through npx reason:mcp.jsonusescommand: "npx"with-y convex@latest mcp startin committed plugin MCP config. problem: mutable package launcher in committed MCP configolostep/olostep-cursor-plugin:SEC329atmcp.json-confirmed_issue- committed MCP config launches through npx reason:mcp.jsonusescommand: "npx"with-y olostep-mcpin committed MCP server config. problem: mutable package launcher in committed MCP configvan-reflect/cursor-plugin:SEC329at.mcp.json-confirmed_issue- committed MCP config launches through npx reason:.mcp.jsonusescommand: "npx"with-y reflect-memory-mcpin committed MCP server config. problem: mutable package launcher in committed MCP config
Preview Usefulness Summary
Wave 2 produced 1140 preview finding(s).
datadog-labs/cursor-plugin:stayed unchangedcontainers/kubernetes-mcp-server:3preview finding(s) viaSEC328modelcontextprotocol/registry:10preview finding(s) viaSEC328airmcp-com/mcp-standards:18preview finding(s) viaSEC328,SEC347,SEC361,SEC381,SEC382,SEC385,SEC386,SEC387,SEC388,SEC399,SEC406centminmod/my-claude-code-setup:5preview finding(s) viaSEC361,SEC381,SEC382,SEC483olostep/olostep-cursor-plugin:2preview finding(s) viaSEC347cloudflare/mcp-server-cloudflare:1preview finding(s) viaSEC328googleworkspace/developer-tools:2preview finding(s) viaSEC328hashicorp/terraform-mcp-server:1preview finding(s) viaSEC328github/github-mcp-server:10preview finding(s) viaSEC325,SEC328docker/hub-mcp:6preview finding(s) viaSEC328TencentCloudBase/CloudBase-MCP:11preview finding(s) viaSEC328,SEC347,SEC360,SEC361,SEC380gitkraken/MCP-Docs:1preview finding(s) viaSEC328VictoriaMetrics-Community/mcp-victoriametrics:5preview finding(s) viaSEC328OriShmila/alpha-vantage-mcp-server:1preview finding(s) viaSEC347blockscout/mcp-server:40preview finding(s) viaSEC328,SEC360,SEC361,SEC378,SEC380,SEC381,SEC382,SEC407,SEC409,SEC410anthropics/claude-plugins-official:1preview finding(s) viaSEC347affaan-m/everything-claude-code:8preview finding(s) viaSEC313,SEC328,SEC347jeremylongshore/claude-code-plugins-plus-skills:921preview finding(s) viaSEC102,SEC105,SEC313,SEC328,SEC347,SEC348,SEC351,SEC389,SEC404,SEC419get-convex/convex-agent-plugins:17preview finding(s) viaSEC378agent-sh/agentsys:6preview finding(s) viaSEC102,SEC328,SEC351,SEC361giuseppe-trisciuoglio/developer-kit-claude-code:6preview finding(s) viaSEC328,SEC348,SEC404agent-sh/agnix:27preview finding(s) viaSEC325,SEC328zebbern/claude-code-guide:8preview finding(s) viaSEC313,SEC335,SEC348zechenzhangAGI/AI-research-SKILLs:8preview finding(s) viaSEC328,SEC348,SEC349,SEC351buildingopen/claude-setup:5preview finding(s) viaSEC351,SEC361,SEC363,SEC381,SEC382alirezarezvani/claude-skills:5preview finding(s) viaSEC105,SEC328trailofbits/skills:9preview finding(s) viaSEC313,SEC348,SEC349,SEC389,SEC404,SEC419Jeffallan/claude-skills:2preview finding(s) viaSEC328,SEC347coleam00/second-brain-skills:1preview finding(s) viaSEC347
Runtime / Diagnostic Notes
cursor/plugins:stayed unchangedEmmraan/agent-skills:stayed unchanged
Top FP Clusters
- No false-positive cluster observed in this wave.
- No false-positive cluster observed in this wave.
- No false-positive cluster observed in this wave.
Top FN Clusters
- No false-negative cluster observed in this wave.
- No false-negative cluster observed in this wave.
- No false-negative cluster observed in this wave.
Recommended Next Step
credible prod evidence for default precision
Rationale:
- this report is grounded in the current checked-in wave 3 ledger and archived wave 2 baseline
- recommended stable precision is now evaluated from explicit preset-lane evidence and structured adjudications
- ownership split is now a checked-in part of the evidence model instead of an informal reading of repo owners
- cohort size reached the
48-repo bar and official coverage reached the12-repo target - every currently observed
recommendedstable hit has an adjudication and none of them is markedfalse_positive